{"grype_matches":[{"artifact":{"id":"dbc19132357243c6","cpes":["cpe:2.3:a:org.springframework:spring-beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-beans:spring-beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-beans:spring_beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_beans:spring-beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_beans:spring_beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_beans:5.0.8.RELEASE:*:*:*:*:*:*:*"],"name":"spring-beans","purl":"pkg:maven/org.springframework/spring-beans@5.0.8.RELEASE","type":"java-archive","version":"5.0.8.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-beans-5.0.8.RELEASE.jar","manifestName":"","pomArtifactID":"spring-beans","archiveDigests":[{"value":"5fc965d3e7f5515099244857a8ae9e2a208c169b","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-beans-5.0.8.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.2.20.RELEASE"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-36p3-wjmg-h94x","versionConstraint":"<5.2.20.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-beans","version":"5.0.8.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-36p3-wjmg-h94x","fix":{"state":"fixed","versions":["5.2.20.RELEASE"],"available":[{"date":"2022-12-16","kind":"first-observed","version":"5.2.20.RELEASE"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22965","date":"2026-10-08","epss":0.99638,"percentile":0.99949}],"risk":98.70000000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965","https://github.com/spring-projects/spring-framework/commit/002546b3e4b8d791ea6acccb81eb3168f51abb15","https://github.com/spring-projects/spring-boot/releases/tag/v2.5.12","https://github.com/spring-projects/spring-boot/releases/tag/v2.6.6","https://github.com/spring-projects/spring-framework/releases/tag/v5.2.20.RELEASE","https://github.com/spring-projects/spring-framework/releases/tag/v5.3.18","https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement","https://tanzu.vmware.com/security/cve-2022-22965","https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67","https://www.oracle.com/security-alerts/cpuapr2022.html","http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html","http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.kb.cert.org/vuls/id/970766","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-36p3-wjmg-h94x","description":"Remote Code Execution in Spring Framework","knownExploited":[{"cve":"CVE-2022-22965","cwes":["CWE-94"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965"],"dueDate":"2022-04-25","product":"Spring Framework","dateAdded":"2022-04-04","vendorProject":"VMware","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2022-22965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22965","date":"2026-10-08","epss":0.99638,"percentile":0.99949}],"urls":["http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html","http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html","https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005","https://tanzu.vmware.com/security/cve-2022-22965","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.kb.cert.org/vuls/id/970766","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22965","description":"A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.","knownExploited":[{"cve":"CVE-2022-22965","cwes":["CWE-94"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965"],"dueDate":"2022-04-25","product":"Spring Framework","dateAdded":"2022-04-04","vendorProject":"VMware","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"f4cb0151cd6ef516","cpes":["cpe:2.3:a:org.springframework.boot:spring-boot-starter-web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.boot:spring_boot_starter_web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot-starter-web:spring-boot-starter-web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot-starter-web:spring_boot_starter_web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot_starter_web:spring-boot-starter-web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot_starter_web:spring_boot_starter_web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot-starter:spring-boot-starter-web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot-starter:spring_boot_starter_web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot_starter:spring-boot-starter-web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot_starter:spring_boot_starter_web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-boot-starter-web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_boot_starter_web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot:spring-boot-starter-web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot:spring_boot_starter_web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot:spring-boot-starter-web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot:spring_boot_starter_web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-boot-starter-web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_boot_starter_web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.boot:boot:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:boot:spring-boot-starter-web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:boot:spring_boot_starter_web:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot-starter-web:boot:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot_starter_web:boot:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot-starter:boot:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot_starter:boot:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:boot:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot:boot:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot:boot:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:boot:2.0.4.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:boot:boot:2.0.4.RELEASE:*:*:*:*:*:*:*"],"name":"spring-boot-starter-web","purl":"pkg:maven/org.springframework.boot/spring-boot-starter-web@2.0.4.RELEASE","type":"java-archive","version":"2.0.4.RELEASE","language":"java","licenses":[],"metadata":{"pomGroupID":"org.springframework.boot","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-boot-starter-web-2.0.4.RELEASE.jar","manifestName":"","pomArtifactID":"spring-boot-starter-web","archiveDigests":[{"value":"98d49e981ecf804da877d84259b7b0d1ec2fb6f6","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-boot-starter-web-2.0.4.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.5.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-36p3-wjmg-h94x","versionConstraint":"<2.5.12 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework.boot:spring-boot-starter-web","version":"2.0.4.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-36p3-wjmg-h94x","fix":{"state":"fixed","versions":["2.5.12"],"available":[{"date":"2022-04-01","kind":"first-observed","version":"2.5.12"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22965","date":"2026-10-08","epss":0.99638,"percentile":0.99949}],"risk":98.70000000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965","https://github.com/spring-projects/spring-framework/commit/002546b3e4b8d791ea6acccb81eb3168f51abb15","https://github.com/spring-projects/spring-boot/releases/tag/v2.5.12","https://github.com/spring-projects/spring-boot/releases/tag/v2.6.6","https://github.com/spring-projects/spring-framework/releases/tag/v5.2.20.RELEASE","https://github.com/spring-projects/spring-framework/releases/tag/v5.3.18","https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement","https://tanzu.vmware.com/security/cve-2022-22965","https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67","https://www.oracle.com/security-alerts/cpuapr2022.html","http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html","http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.kb.cert.org/vuls/id/970766","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-36p3-wjmg-h94x","description":"Remote Code Execution in Spring Framework","knownExploited":[{"cve":"CVE-2022-22965","cwes":["CWE-94"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965"],"dueDate":"2022-04-25","product":"Spring Framework","dateAdded":"2022-04-04","vendorProject":"VMware","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2022-22965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22965","date":"2026-10-08","epss":0.99638,"percentile":0.99949}],"urls":["http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html","http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html","https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005","https://tanzu.vmware.com/security/cve-2022-22965","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.kb.cert.org/vuls/id/970766","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22965","description":"A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.","knownExploited":[{"cve":"CVE-2022-22965","cwes":["CWE-94"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965"],"dueDate":"2022-04-25","product":"Spring Framework","dateAdded":"2022-04-04","vendorProject":"VMware","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"f86d3c9a089379e7","cpes":["cpe:2.3:a:org.springframework:spring-webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-webmvc:spring-webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-webmvc:spring_webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_webmvc:spring-webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_webmvc:spring_webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*"],"name":"spring-webmvc","purl":"pkg:maven/org.springframework/spring-webmvc@5.0.8.RELEASE","type":"java-archive","version":"5.0.8.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-webmvc-5.0.8.RELEASE.jar","manifestName":"","pomArtifactID":"spring-webmvc","archiveDigests":[{"value":"7e5fe57590ca8e4468e50fe1d92b0b67aa4a327a","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-webmvc-5.0.8.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.2.20.RELEASE"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-36p3-wjmg-h94x","versionConstraint":"<5.2.20.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-webmvc","version":"5.0.8.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-36p3-wjmg-h94x","fix":{"state":"fixed","versions":["5.2.20.RELEASE"],"available":[{"date":"2022-12-16","kind":"first-observed","version":"5.2.20.RELEASE"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22965","date":"2026-10-08","epss":0.99638,"percentile":0.99949}],"risk":98.70000000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965","https://github.com/spring-projects/spring-framework/commit/002546b3e4b8d791ea6acccb81eb3168f51abb15","https://github.com/spring-projects/spring-boot/releases/tag/v2.5.12","https://github.com/spring-projects/spring-boot/releases/tag/v2.6.6","https://github.com/spring-projects/spring-framework/releases/tag/v5.2.20.RELEASE","https://github.com/spring-projects/spring-framework/releases/tag/v5.3.18","https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement","https://tanzu.vmware.com/security/cve-2022-22965","https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67","https://www.oracle.com/security-alerts/cpuapr2022.html","http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html","http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.kb.cert.org/vuls/id/970766","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-36p3-wjmg-h94x","description":"Remote Code Execution in Spring Framework","knownExploited":[{"cve":"CVE-2022-22965","cwes":["CWE-94"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965"],"dueDate":"2022-04-25","product":"Spring Framework","dateAdded":"2022-04-04","vendorProject":"VMware","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2022-22965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22965","date":"2026-10-08","epss":0.99638,"percentile":0.99949}],"urls":["http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html","http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html","https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005","https://tanzu.vmware.com/security/cve-2022-22965","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.kb.cert.org/vuls/id/970766","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22965","description":"A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.","knownExploited":[{"cve":"CVE-2022-22965","cwes":["CWE-94"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965"],"dueDate":"2022-04-25","product":"Spring Framework","dateAdded":"2022-04-04","vendorProject":"VMware","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.51"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c9hw-wf7x-jp9j","versionConstraint":">=8.0.0,<8.5.51 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c9hw-wf7x-jp9j","fix":{"state":"fixed","versions":["8.5.51"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"8.5.51"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1938","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1938","date":"2026-10-08","epss":0.9927,"percentile":0.99937}],"risk":98.70000000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-1938","https://lists.apache.org/thread.html/r089dc67c0358a1556dd279c762c74f32d7a254a54836b7ee2d839d8e@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r17aaa3a05b5b7fe9075613dd0c681efa60a4f8c8fbad152c61371b6e@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r38a5b7943b9a62ecb853acc22ef08ff586a7b3c66e08f949f0396ab1@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r43faacf64570b1d9a4bada407a5af3b2738b0c007b905f1b6b608c65@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r4afa11e0464408e68f0e9560e90b185749363a66398b1491254f7864@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r4f86cb260196e5cfcbbe782822c225ddcc70f54560f14a8f11c6926f@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r549b43509e387a42656f0641fa311bf27c127c244fe02007d5b8d6f6@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r5e2f1201b92ee05a0527cfc076a81ea0c270be299b87895c0ddbe02b@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r61f280a76902b594692f0b24a1dbf647bb5a4c197b9395e9a6796e7c@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6a5633cad1b560a1e51f5b425f02918bdf30e090fdf18c5f7c2617eb@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r74328b178f9f37fe759dffbc9c1f2793e66d79d7a8a20d3836551794@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r75113652e46c4dee687236510649acfb70d2c63e074152049c3f399d@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r772335e6851ad33ddb076218fa4ff70de1bf398d5b43e2ddf0130e5d@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7c6f492fbd39af34a68681dbbba0468490ff1a97a1bd79c6a53610ef%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r856cdd87eda7af40b50278d6de80ee4b42d63adeb433a34a7bdaf9db@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r9f119d9ce9239114022e13dbfe385b3de7c972f24f05d6dbd35c1a2f@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rad36ec6a1ffc9e43266b030c22ceeea569243555d34fb4187ff08522@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rb2fc890bef23cbc7f343900005fe1edd3b091cf18dada455580258f9@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rbdb1d2b651a3728f0ceba9e0853575b6f90296a94a71836a15f7364a@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc068e824654c4b8bd4f2490bec869e29edbfcd5dfe02d47cbf7433b2@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rcd5cd301e9e7e39f939baf2f5d58704750be07a5e2d3393e40ca7194@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rce2af55f6e144ffcdc025f997eddceb315dfbc0b230e3d750a7f7425@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rd0774c95699d5aeb5e16e9a600fb2ea296e81175e30a62094e27e3e7@%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rd50baccd1bbb96c2327d5a8caa25a49692b3d68d96915bd1cfbb9f8b@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/re5eecbe5bf967439bafeeaa85987b3a43f0e6efe06b6976ee768cde2@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf26663f42e7f1a1d1cac732469fb5e92c89908a48b61ec546dbb79ca@%3Cbugs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rf992c5adf376294af31378a70aa8a158388a41d7039668821be28df3@%3Ccommits.tomee.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","https://security.gentoo.org/glsa/202003-43","https://www.debian.org/security/2020/dsa-4673","https://www.debian.org/security/2020/dsa-4680","http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html","http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00002.html","http://support.blackberry.com/kb/articleDetail?articleNumber=000062739","https://lists.apache.org/thread.html/r8f7484589454638af527182ae55ef5b628ba00c05c5b11887c922fb1@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/ra7092f7492569b39b04ec0decf52628ba86c51f15efb38f5853e2760@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed@%3Cdev.tomcat.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r92d78655c068d0bc991d1edbdfb24f9c5134603e647cade1113d4e0a@%3Cusers.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r47caef01f663106c2bb81d116b8380d62beac9e543dd3f3bc2c2beda@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r57f5e4ced436ace518a9e222fabe27fb785f09f5bf974814cc48ca97@%3Ccommits.tomee.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/re5eecbe5bf967439bafeeaa85987b3a43f0e6efe06b6976ee768cde2%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd50baccd1bbb96c2327d5a8caa25a49692b3d68d96915bd1cfbb9f8b%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd0774c95699d5aeb5e16e9a600fb2ea296e81175e30a62094e27e3e7%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rce2af55f6e144ffcdc025f997eddceb315dfbc0b230e3d750a7f7425%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rcd5cd301e9e7e39f939baf2f5d58704750be07a5e2d3393e40ca7194%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc068e824654c4b8bd4f2490bec869e29edbfcd5dfe02d47cbf7433b2%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rbdb1d2b651a3728f0ceba9e0853575b6f90296a94a71836a15f7364a%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rb2fc890bef23cbc7f343900005fe1edd3b091cf18dada455580258f9%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rad36ec6a1ffc9e43266b030c22ceeea569243555d34fb4187ff08522%40%3Cnotifications.ofbiz.apache.org%3E","https://security.netapp.com/advisory/ntap-20200226-0002","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L46WJIV6UV3FWA5O5YEY6XLA73RYD53B","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/K3IPNHCKFVUKSHDTM45UL4Q765EHHTFG","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2XFLQB3O5QVP4ZBIPVIXBEZV7F2R7ZMS","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L46WJIV6UV3FWA5O5YEY6XLA73RYD53B","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3IPNHCKFVUKSHDTM45UL4Q765EHHTFG","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2XFLQB3O5QVP4ZBIPVIXBEZV7F2R7ZMS","https://lists.apache.org/thread.html/rf992c5adf376294af31378a70aa8a158388a41d7039668821be28df3%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf26663f42e7f1a1d1cac732469fb5e92c89908a48b61ec546dbb79ca%40%3Cbugs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r5e2f1201b92ee05a0527cfc076a81ea0c270be299b87895c0ddbe02b%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r57f5e4ced436ace518a9e222fabe27fb785f09f5bf974814cc48ca97%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r549b43509e387a42656f0641fa311bf27c127c244fe02007d5b8d6f6%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r4f86cb260196e5cfcbbe782822c225ddcc70f54560f14a8f11c6926f%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r4afa11e0464408e68f0e9560e90b185749363a66398b1491254f7864%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r47caef01f663106c2bb81d116b8380d62beac9e543dd3f3bc2c2beda%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r43faacf64570b1d9a4bada407a5af3b2738b0c007b905f1b6b608c65%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r38a5b7943b9a62ecb853acc22ef08ff586a7b3c66e08f949f0396ab1%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r17aaa3a05b5b7fe9075613dd0c681efa60a4f8c8fbad152c61371b6e%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r089dc67c0358a1556dd279c762c74f32d7a254a54836b7ee2d839d8e%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/ra7092f7492569b39b04ec0decf52628ba86c51f15efb38f5853e2760%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r9f119d9ce9239114022e13dbfe385b3de7c972f24f05d6dbd35c1a2f%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r92d78655c068d0bc991d1edbdfb24f9c5134603e647cade1113d4e0a%40%3Cusers.tomee.apache.org%3E","https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r8f7484589454638af527182ae55ef5b628ba00c05c5b11887c922fb1%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r856cdd87eda7af40b50278d6de80ee4b42d63adeb433a34a7bdaf9db%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r772335e6851ad33ddb076218fa4ff70de1bf398d5b43e2ddf0130e5d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r75113652e46c4dee687236510649acfb70d2c63e074152049c3f399d%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r74328b178f9f37fe759dffbc9c1f2793e66d79d7a8a20d3836551794%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r6a5633cad1b560a1e51f5b425f02918bdf30e090fdf18c5f7c2617eb%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r61f280a76902b594692f0b24a1dbf647bb5a4c197b9395e9a6796e7c%40%3Cusers.tomcat.apache.org%3E","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1938"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c9hw-wf7x-jp9j","description":"Improper Privilege Management in Tomcat","knownExploited":[{"cve":"CVE-2020-1938","urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-1938"],"dueDate":"2022-03-17","product":"Tomcat","dateAdded":"2022-03-03","vendorProject":"Apache","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2020-1938","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1938","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1938","date":"2026-10-08","epss":0.9927,"percentile":0.99937}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html","http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00002.html","http://support.blackberry.com/kb/articleDetail?articleNumber=000062739","https://lists.apache.org/thread.html/r089dc67c0358a1556dd279c762c74f32d7a254a54836b7ee2d839d8e%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r17aaa3a05b5b7fe9075613dd0c681efa60a4f8c8fbad152c61371b6e%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r38a5b7943b9a62ecb853acc22ef08ff586a7b3c66e08f949f0396ab1%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r43faacf64570b1d9a4bada407a5af3b2738b0c007b905f1b6b608c65%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r47caef01f663106c2bb81d116b8380d62beac9e543dd3f3bc2c2beda%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r4afa11e0464408e68f0e9560e90b185749363a66398b1491254f7864%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r4f86cb260196e5cfcbbe782822c225ddcc70f54560f14a8f11c6926f%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r549b43509e387a42656f0641fa311bf27c127c244fe02007d5b8d6f6%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r57f5e4ced436ace518a9e222fabe27fb785f09f5bf974814cc48ca97%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r5e2f1201b92ee05a0527cfc076a81ea0c270be299b87895c0ddbe02b%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r61f280a76902b594692f0b24a1dbf647bb5a4c197b9395e9a6796e7c%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6a5633cad1b560a1e51f5b425f02918bdf30e090fdf18c5f7c2617eb%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r74328b178f9f37fe759dffbc9c1f2793e66d79d7a8a20d3836551794%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r75113652e46c4dee687236510649acfb70d2c63e074152049c3f399d%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r772335e6851ad33ddb076218fa4ff70de1bf398d5b43e2ddf0130e5d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7c6f492fbd39af34a68681dbbba0468490ff1a97a1bd79c6a53610ef%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r856cdd87eda7af40b50278d6de80ee4b42d63adeb433a34a7bdaf9db%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r8f7484589454638af527182ae55ef5b628ba00c05c5b11887c922fb1%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r92d78655c068d0bc991d1edbdfb24f9c5134603e647cade1113d4e0a%40%3Cusers.tomee.apache.org%3E","https://lists.apache.org/thread.html/r9f119d9ce9239114022e13dbfe385b3de7c972f24f05d6dbd35c1a2f%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/ra7092f7492569b39b04ec0decf52628ba86c51f15efb38f5853e2760%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rad36ec6a1ffc9e43266b030c22ceeea569243555d34fb4187ff08522%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb2fc890bef23cbc7f343900005fe1edd3b091cf18dada455580258f9%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rbdb1d2b651a3728f0ceba9e0853575b6f90296a94a71836a15f7364a%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc068e824654c4b8bd4f2490bec869e29edbfcd5dfe02d47cbf7433b2%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rcd5cd301e9e7e39f939baf2f5d58704750be07a5e2d3393e40ca7194%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rce2af55f6e144ffcdc025f997eddceb315dfbc0b230e3d750a7f7425%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rd0774c95699d5aeb5e16e9a600fb2ea296e81175e30a62094e27e3e7%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rd50baccd1bbb96c2327d5a8caa25a49692b3d68d96915bd1cfbb9f8b%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/re5eecbe5bf967439bafeeaa85987b3a43f0e6efe06b6976ee768cde2%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rf26663f42e7f1a1d1cac732469fb5e92c89908a48b61ec546dbb79ca%40%3Cbugs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rf992c5adf376294af31378a70aa8a158388a41d7039668821be28df3%40%3Ccommits.tomee.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2XFLQB3O5QVP4ZBIPVIXBEZV7F2R7ZMS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3IPNHCKFVUKSHDTM45UL4Q765EHHTFG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L46WJIV6UV3FWA5O5YEY6XLA73RYD53B/","https://security.gentoo.org/glsa/202003-43","https://security.netapp.com/advisory/ntap-20200226-0002/","https://www.debian.org/security/2020/dsa-4673","https://www.debian.org/security/2020/dsa-4680","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1938"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1938","description":"When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.","knownExploited":[{"cve":"CVE-2020-1938","urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-1938"],"dueDate":"2022-03-17","product":"Tomcat","dateAdded":"2022-03-03","vendorProject":"Apache","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-83qj-6fr2-vhqg","versionConstraint":">=8.5.0,<=8.5.100 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-83qj-6fr2-vhqg","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-24813","cwe":"CWE-44","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2025-24813","cwe":"CWE-502","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2025-24813","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-24813","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-24813","date":"2026-10-08","epss":0.99927,"percentile":0.99969}],"risk":97.125,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-24813","https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq","http://www.openwall.com/lists/oss-security/2025/03/10/5","https://github.com/apache/tomcat/commit/0a668e0c27f2b7ca0cc7c6eea32253b9b5ecb29c","https://github.com/apache/tomcat/commit/eb61aade8f8daccaecabf07d428b877975622f72","https://github.com/apache/tomcat/commit/f6c01d6577cf9a1e06792be47e623d36acc3b5dc","https://github.com/absholi7ly/POC-CVE-2025-24813/blob/main/README.md","https://www.vicarius.io/vsociety/posts/cve-2025-24813-detect-apache-tomcat-rce","https://www.vicarius.io/vsociety/posts/cve-2025-24813-mitigate-apache-tomcat-rce","https://security.netapp.com/advisory/ntap-20250321-0001","https://lists.debian.org/debian-lts-announce/2025/04/msg00003.html","https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-detect-vulnerability","https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-mitigation-vulnerability","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24813"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-83qj-6fr2-vhqg","description":"Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT","knownExploited":[{"cve":"CVE-2025-24813","cwes":["CWE-44","CWE-502"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-24813"],"notes":"This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq","dueDate":"2025-04-22","product":"Tomcat","dateAdded":"2025-04-01","vendorProject":"Apache","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2025-24813","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-24813","cwe":"CWE-44","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2025-24813","cwe":"CWE-502","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2025-24813","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-24813","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-24813","date":"2026-10-08","epss":0.99927,"percentile":0.99969}],"urls":["https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq","http://www.openwall.com/lists/oss-security/2025/03/10/5","https://lists.debian.org/debian-lts-announce/2025/04/msg00003.html","https://security.netapp.com/advisory/ntap-20250321-0001/","https://www.vicarius.io/vsociety/posts/cve-2025-24813-detect-apache-tomcat-rce","https://www.vicarius.io/vsociety/posts/cve-2025-24813-mitigate-apache-tomcat-rce","https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-detect-vulnerability","https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-mitigation-vulnerability","https://github.com/absholi7ly/POC-CVE-2025-24813/blob/main/README.md","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24813"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-24813","description":"Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions \nmay also be affected.\n\n\nIf all of the following were true, a malicious user was able to view       security sensitive files and/or inject content into those files:\n- writes enabled for the default servlet (disabled by default)\n- support for partial PUT (enabled by default)\n- a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads\n- attacker knowledge of the names of security sensitive files being uploaded\n- the security sensitive files also being uploaded via partial PUT\n\nIf all of the following were true, a malicious user was able to       perform remote code execution:\n- writes enabled for the default servlet (disabled by default)\n- support for partial PUT (enabled by default)\n- application was using Tomcat's file based session persistence with the default storage location\n- application included a library that may be leveraged in a deserialization attack\n\nUsers are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.","knownExploited":[{"cve":"CVE-2025-24813","cwes":["CWE-44","CWE-502"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-24813"],"notes":"This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq","dueDate":"2025-04-22","product":"Tomcat","dateAdded":"2025-04-01","vendorProject":"Apache","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"839771142f972cee","cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*"],"name":"libnghttp2-14","purl":"pkg:deb/ubuntu/libnghttp2-14@1.30.0-1ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=nghttp2","type":"deb","version":"1.30.0-1ubuntu1","language":"","licenses":["BSD-2-clause","Expat","GPL-3","GPL-3+","MIT","SIL-OFL-1.1","all-permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnghttp2-14/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libnghttp2-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nghttp2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-44487","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nghttp2","version":"1.30.0-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-44487","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-44487","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-44487","date":"2026-10-08","epss":0.99999,"percentile":0.99998}],"risk":78.75000000000001,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-44487","knownExploited":[{"cve":"CVE-2023-44487","cwes":["CWE-400"],"urls":["https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/","https://nvd.nist.gov/vuln/detail/CVE-2023-44487"],"notes":"This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487","dueDate":"2023-10-31","product":"HTTP/2","dateAdded":"2023-10-10","vendorProject":"IETF","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2023-44487","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-44487","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-44487","date":"2026-10-08","epss":0.99999,"percentile":0.99998}],"urls":["http://www.openwall.com/lists/oss-security/2023/10/10/6","http://www.openwall.com/lists/oss-security/2023/10/10/7","http://www.openwall.com/lists/oss-security/2023/10/13/4","http://www.openwall.com/lists/oss-security/2023/10/13/9","http://www.openwall.com/lists/oss-security/2023/10/18/4","http://www.openwall.com/lists/oss-security/2023/10/18/8","http://www.openwall.com/lists/oss-security/2023/10/19/6","http://www.openwall.com/lists/oss-security/2023/10/20/8","https://access.redhat.com/security/cve/cve-2023-44487","https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/","https://aws.amazon.com/security/security-bulletins/AWS-2023-011/","https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/","https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/","https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/","https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack","https://blog.vespa.ai/cve-2023-44487/","https://bugzilla.proxmox.com/show_bug.cgi?id=4988","https://bugzilla.redhat.com/show_bug.cgi?id=2242803","https://bugzilla.suse.com/show_bug.cgi?id=1216123","https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9","https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/","https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack","https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125","https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715","https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve","https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764","https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088","https://github.com/Azure/AKS/issues/3947","https://github.com/Kong/kong/discussions/11741","https://github.com/advisories/GHSA-qppj-fm5r-hxr3","https://github.com/advisories/GHSA-vx74-f528-fxqg","https://github.com/advisories/GHSA-xpw8-rcwv-8f8p","https://github.com/akka/akka-http/issues/4323","https://github.com/alibaba/tengine/issues/1872","https://github.com/apache/apisix/issues/10320","https://github.com/apache/httpd-site/pull/10","https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113","https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2","https://github.com/apache/trafficserver/pull/10564","https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487","https://github.com/bcdannyboy/CVE-2023-44487","https://github.com/caddyserver/caddy/issues/5877","https://github.com/caddyserver/caddy/releases/tag/v2.7.5","https://github.com/dotnet/announcements/issues/277","https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73","https://github.com/eclipse/jetty.project/issues/10679","https://github.com/envoyproxy/envoy/pull/30055","https://github.com/etcd-io/etcd/issues/16740","https://github.com/facebook/proxygen/pull/466","https://github.com/golang/go/issues/63417","https://github.com/grpc/grpc-go/pull/6703","https://github.com/grpc/grpc/releases/tag/v1.59.2","https://github.com/h2o/h2o/pull/3291","https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf","https://github.com/haproxy/haproxy/issues/2312","https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244","https://github.com/junkurihara/rust-rpxy/issues/97","https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1","https://github.com/kazu-yamamoto/http2/issues/93","https://github.com/kubernetes/kubernetes/pull/121120","https://github.com/line/armeria/pull/5232","https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632","https://github.com/micrictor/http2-rst-stream","https://github.com/microsoft/CBL-Mariner/pull/6381","https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61","https://github.com/nghttp2/nghttp2/pull/1961","https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0","https://github.com/ninenines/cowboy/issues/1615","https://github.com/nodejs/node/pull/50121","https://github.com/openresty/openresty/issues/930","https://github.com/opensearch-project/data-prepper/issues/3474","https://github.com/oqtane/oqtane.framework/discussions/3367","https://github.com/projectcontour/contour/pull/5826","https://github.com/tempesta-tech/tempesta/issues/1986","https://github.com/varnishcache/varnish-cache/issues/3996","https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo","https://istio.io/latest/news/security/istio-security-2023-004/","https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/","https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q","https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html","https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html","https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/","https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html","https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html","https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html","https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487","https://my.f5.com/manage/s/article/K000137106","https://netty.io/news/2023/10/10/4-1-100-Final.html","https://news.ycombinator.com/item?id=37830987","https://news.ycombinator.com/item?id=37830998","https://news.ycombinator.com/item?id=37831062","https://news.ycombinator.com/item?id=37837043","https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/","https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected","https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ","https://security.gentoo.org/glsa/202311-09","https://security.netapp.com/advisory/ntap-20231016-0001/","https://security.netapp.com/advisory/ntap-20240426-0007/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://security.netapp.com/advisory/ntap-20240621-0007/","https://security.paloaltonetworks.com/CVE-2023-44487","https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14","https://ubuntu.com/security/CVE-2023-44487","https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/","https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487","https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event","https://www.debian.org/security/2023/dsa-5521","https://www.debian.org/security/2023/dsa-5522","https://www.debian.org/security/2023/dsa-5540","https://www.debian.org/security/2023/dsa-5549","https://www.debian.org/security/2023/dsa-5558","https://www.debian.org/security/2023/dsa-5570","https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487","https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/","https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/","https://www.openwall.com/lists/oss-security/2023/10/10/6","https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack","https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/","http://www.openwall.com/lists/oss-security/2025/08/13/6","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/","https://www.vicarius.io/vsociety/posts/rapid-reset-cve-2023-44487-dos-in-http2-understanding-the-root-cause","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-341067.html","https://cert-portal.siemens.com/productcert/html/ssa-784301.html","https://cert-portal.siemens.com/productcert/html/ssa-832273.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44487","https://github.com/envoyproxy/envoy/security/advisories/GHSA-jhv4-f7mr-xx76","https://github.com/kubernetes/ingress-nginx/blob/4b5c5efe2508dc915a48c54de7f23912ff2ec695/changelog/controller-1.9.3.md?plain=1#L15","https://varnish-cache.org/releases/rel6.0.12.html#rel6-0-12","https://varnish-cache.org/releases/rel7.3.1.html#rel7-3-1","https://varnish-cache.org/releases/rel7.4.2.html#rel7-4-2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-44487","description":"The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.","knownExploited":[{"cve":"CVE-2023-44487","cwes":["CWE-400"],"urls":["https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/","https://nvd.nist.gov/vuln/detail/CVE-2023-44487"],"notes":"This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487","dueDate":"2023-10-31","product":"HTTP/2","dateAdded":"2023-10-10","vendorProject":"IETF","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"1aef213d2b0dcd29","cpes":["cpe:2.3:a:libfreetype6:libfreetype6:2.8.1-2ubuntu2:*:*:*:*:*:*:*"],"name":"libfreetype6","purl":"pkg:deb/ubuntu/libfreetype6@2.8.1-2ubuntu2?arch=amd64&distro=ubuntu-18.04&upstream=freetype","type":"deb","version":"2.8.1-2ubuntu2","language":"","licenses":["BSD-2-Clause","BSD-3-Clause","Catharon-OSL","FTL","GPL-2","GPL-2+","GZip","OpenGroup-BSD-like"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfreetype6/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libfreetype6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"freetype"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.1-2ubuntu2.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-15999","versionConstraint":"< 2.8.1-2ubuntu2.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"freetype","version":"2.8.1-2ubuntu2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-15999","fix":{"state":"fixed","versions":["2.8.1-2ubuntu2.1"],"available":[{"date":"2020-10-20","kind":"advisory","version":"2.8.1-2ubuntu2.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-15999","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-15999","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-15999","date":"2026-10-08","epss":0.63894,"percentile":0.99206}],"risk":78.75000000000001,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-15999","knownExploited":[{"cve":"CVE-2020-15999","cwes":["CWE-787"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-15999"],"dueDate":"2021-11-17","product":"Chrome FreeType","dateAdded":"2021-11-03","vendorProject":"Google","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2020-15999","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-15999","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-15999","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-15999","date":"2026-10-08","epss":0.63894,"percentile":0.99206}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00016.html","http://seclists.org/fulldisclosure/2020/Nov/33","https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html","https://crbug.com/1139963","https://googleprojectzero.blogspot.com/p/rca-cve-2020-15999.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J3QVIGAAJ4D62YEJAJJWMCCBCOQ6TVL7/","https://security.gentoo.org/glsa/202011-12","https://security.gentoo.org/glsa/202012-04","https://security.gentoo.org/glsa/202401-19","https://www.debian.org/security/2021/dsa-4824","https://security.netapp.com/advisory/ntap-20240812-0001/","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-15999"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-15999","description":"Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.","knownExploited":[{"cve":"CVE-2020-15999","cwes":["CWE-787"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-15999"],"dueDate":"2021-11-17","product":"Chrome FreeType","dateAdded":"2021-11-03","vendorProject":"Google","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"f2b3aae4ffb91c19","cpes":["cpe:2.3:a:org.yaml.snakeyaml:snakeyaml:1.19:*:*:*:*:*:*:*","cpe:2.3:a:snakeyaml:snakeyaml:1.19:*:*:*:*:*:*:*","cpe:2.3:a:org.yaml:snakeyaml:1.19:*:*:*:*:*:*:*","cpe:2.3:a:yaml:snakeyaml:1.19:*:*:*:*:*:*:*"],"name":"snakeyaml","purl":"pkg:maven/org.yaml/snakeyaml@1.19","type":"java-archive","version":"1.19","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.yaml","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/snakeyaml-1.19.jar","manifestName":"","pomArtifactID":"snakeyaml","archiveDigests":[{"value":"2d998d3d674b172a588e54ab619854d073f555b5","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/snakeyaml-1.19.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mjmj-j48q-9wg2","versionConstraint":"<=1.33 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.yaml:snakeyaml","version":"1.19"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mjmj-j48q-9wg2","fix":{"state":"fixed","versions":["2.0"],"available":[{"date":"2023-03-05","kind":"first-observed","version":"2.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1471","cwe":"CWE-20","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-1471","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1471","date":"2026-10-08","epss":0.99569,"percentile":0.99946}],"risk":78.65951,"urls":["https://github.com/google/security-research/security/advisories/GHSA-mjmj-j48q-9wg2","https://nvd.nist.gov/vuln/detail/CVE-2022-1471","https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64581479","https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64634374","https://bitbucket.org/snakeyaml/snakeyaml/wiki/CVE-2022-1471","https://github.com/mbechler/marshalsec","https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=true","https://bitbucket.org/snakeyaml/snakeyaml/commits/5014df1a36f50aca54405bb8433bc99a8847f758","https://bitbucket.org/snakeyaml/snakeyaml/commits/acc44099f5f4af26ff86b4e4e4cc1c874e2dc5c4","https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64876314","https://groups.google.com/g/kubernetes-security-announce/c/mwrakFaEdnc","http://packetstormsecurity.com/files/175095/PyTorch-Model-Server-Registration-Deserialization-Remote-Code-Execution.html","http://www.openwall.com/lists/oss-security/2023/11/19/1","https://security.netapp.com/advisory/ntap-20230818-0015","https://security.netapp.com/advisory/ntap-20240621-0006","https://snyk.io/blog/unsafe-deserialization-snakeyaml-java-cve-2022-1471","https://confluence.atlassian.com/security/cve-2022-1471-snakeyaml-library-rce-vulnerability-in-multiple-products-1296171009.html","https://infosecwriteups.com/%EF%B8%8F-inside-the-160-comment-fight-to-fix-snakeyamls-rce-default-1a20c5ca4d4c"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mjmj-j48q-9wg2","description":"SnakeYaml Constructor Deserialization Remote Code Execution"},"relatedVulnerabilities":[{"id":"CVE-2022-1471","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1471","cwe":"CWE-20","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-1471","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1471","date":"2026-10-08","epss":0.99569,"percentile":0.99946}],"urls":["http://packetstormsecurity.com/files/175095/PyTorch-Model-Server-Registration-Deserialization-Remote-Code-Execution.html","http://www.openwall.com/lists/oss-security/2023/11/19/1","https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64581479","https://confluence.atlassian.com/security/cve-2022-1471-snakeyaml-library-rce-vulnerability-in-multiple-products-1296171009.html","https://github.com/google/security-research/security/advisories/GHSA-mjmj-j48q-9wg2","https://github.com/mbechler/marshalsec","https://groups.google.com/g/kubernetes-security-announce/c/mwrakFaEdnc","https://infosecwriteups.com/%EF%B8%8F-inside-the-160-comment-fight-to-fix-snakeyamls-rce-default-1a20c5ca4d4c","https://security.netapp.com/advisory/ntap-20230818-0015/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=true"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1471","description":"SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.40"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8vmx-qmch-mpqg","versionConstraint":">=8.0.0,<8.5.40 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-8vmx-qmch-mpqg","fix":{"state":"fixed","versions":["8.5.40"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"8.5.40"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0232","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0232","date":"2026-10-08","epss":0.99923,"percentile":0.99969}],"risk":77.93993999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0232","https://access.redhat.com/errata/RHSA-2019:1712","https://blog.trendmicro.com/trendlabs-security-intelligence/uncovering-cve-2019-0232-a-remote-code-execution-vulnerability-in-apache-tomcat/","https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html","https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/52ffb9fbf661245386a83a661183d13f1de2e5779fa23837a08e02ac@%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/5f297a4b9080b5f65a05bc139596d0e437d6a539b25e31d29d028767@%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/673b6148d92cd7bc99ea2dcf85ad75d57da44fc322d51f37fb529a2a@%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/96849486813a95dfd542e1618b7923ca945508aaf4a4341f674d83e3@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/a6c87a09a71162fd563ab1c4e70a08a103e0b7c199fc391f1c9c4c35@%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/dd4b325cdb261183dbf5ce913c102920a8f09c26dae666a98309165b@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/f4d48b32ef2b6aa49c8830241a9475da5b46e451f964b291c7a0a715@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a@%3Cdev.tomcat.apache.org%3E","https://security.netapp.com/advisory/ntap-20190419-0001/","https://web.archive.org/web/20161228144344/https://blogs.msdn.microsoft.com/twistylittlepassagesallalike/2011/04/23/everyone-quotes-command-line-arguments-the-wrong-way/","https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2019-784","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.synology.com/security/advisory/Synology_SA_19_17","https://wwws.nightwatchcybersecurity.com/2019/04/30/remote-code-execution-rce-in-cgi-servlet-apache-tomcat-on-windows-cve-2019-0232/","http://packetstormsecurity.com/files/153506/Apache-Tomcat-CGIServlet-enableCmdLineArguments-Remote-Code-Execution.html","http://seclists.org/fulldisclosure/2019/May/4","https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/52ffb9fbf661245386a83a661183d13f1de2e5779fa23837a08e02ac%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/5f297a4b9080b5f65a05bc139596d0e437d6a539b25e31d29d028767%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/673b6148d92cd7bc99ea2dcf85ad75d57da44fc322d51f37fb529a2a%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/96849486813a95dfd542e1618b7923ca945508aaf4a4341f674d83e3%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/a6c87a09a71162fd563ab1c4e70a08a103e0b7c199fc391f1c9c4c35%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/dd4b325cdb261183dbf5ce913c102920a8f09c26dae666a98309165b%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/f4d48b32ef2b6aa49c8830241a9475da5b46e451f964b291c7a0a715%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E","https://web.archive.org/web/20200227030103/http://www.securityfocus.com/bid/107906"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8vmx-qmch-mpqg","description":"Apache Tomcat OS Command Injection vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2019-0232","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":9.3,"impactScore":10.1,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0232","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0232","date":"2026-10-08","epss":0.99923,"percentile":0.99969}],"urls":["http://packetstormsecurity.com/files/153506/Apache-Tomcat-CGIServlet-enableCmdLineArguments-Remote-Code-Execution.html","http://seclists.org/fulldisclosure/2019/May/4","http://www.securityfocus.com/bid/107906","https://access.redhat.com/errata/RHSA-2019:1712","https://blog.trendmicro.com/trendlabs-security-intelligence/uncovering-cve-2019-0232-a-remote-code-execution-vulnerability-in-apache-tomcat/","https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html","https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/52ffb9fbf661245386a83a661183d13f1de2e5779fa23837a08e02ac%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/5f297a4b9080b5f65a05bc139596d0e437d6a539b25e31d29d028767%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/673b6148d92cd7bc99ea2dcf85ad75d57da44fc322d51f37fb529a2a%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/96849486813a95dfd542e1618b7923ca945508aaf4a4341f674d83e3%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/a6c87a09a71162fd563ab1c4e70a08a103e0b7c199fc391f1c9c4c35%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/dd4b325cdb261183dbf5ce913c102920a8f09c26dae666a98309165b%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/f4d48b32ef2b6aa49c8830241a9475da5b46e451f964b291c7a0a715%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E","https://security.netapp.com/advisory/ntap-20190419-0001/","https://web.archive.org/web/20161228144344/https://blogs.msdn.microsoft.com/twistylittlepassagesallalike/2011/04/23/everyone-quotes-command-line-arguments-the-wrong-way/","https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2019-784","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.synology.com/security/advisory/Synology_SA_19_17","https://wwws.nightwatchcybersecurity.com/2019/04/30/remote-code-execution-rce-in-cgi-servlet-apache-tomcat-on-windows-cve-2019-0232/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0232","description":"When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to Windows. The CGI Servlet is disabled by default. The CGI option enableCmdLineArguments is disable by default in Tomcat 9.0.x (and will be disabled by default in all versions in response to this vulnerability). For a detailed explanation of the JRE behaviour, see Markus Wulftange's blog (https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html) and this archived MSDN blog (https://web.archive.org/web/20161228144344/https://blogs.msdn.microsoft.com/twistylittlepassagesallalike/2011/04/23/everyone-quotes-command-line-arguments-the-wrong-way/)."}]},{"artifact":{"id":"f86d3c9a089379e7","cpes":["cpe:2.3:a:org.springframework:spring-webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-webmvc:spring-webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-webmvc:spring_webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_webmvc:spring-webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_webmvc:spring_webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*"],"name":"spring-webmvc","purl":"pkg:maven/org.springframework/spring-webmvc@5.0.8.RELEASE","type":"java-archive","version":"5.0.8.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-webmvc-5.0.8.RELEASE.jar","manifestName":"","pomArtifactID":"spring-webmvc","archiveDigests":[{"value":"7e5fe57590ca8e4468e50fe1d92b0b67aa4a327a","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-webmvc-5.0.8.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.0.16.RELEASE"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8wx2-9q48-vm9r","versionConstraint":">=5.0.0.RELEASE,<5.0.16.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-webmvc","version":"5.0.8.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-8wx2-9q48-vm9r","fix":{"state":"fixed","versions":["5.0.16.RELEASE"],"available":[{"date":"2022-12-16","kind":"first-observed","version":"5.0.16.RELEASE"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-5398","cwe":"CWE-79","type":"Secondary","source":"security@pivotal.io"},{"cve":"CVE-2020-5398","cwe":"CWE-494","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-5398","date":"2026-10-08","epss":0.88768,"percentile":0.99775}],"risk":66.57600000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-5398","https://pivotal.io/security/cve-2020-5398","https://lists.apache.org/thread.html/rf8dc72b974ee74f17bce661ea7d124e733a1f4c4f236354ac0cf48e8@%3Ccommits.camel.apache.org%3E","https://lists.apache.org/thread.html/rc05acaacad089613e9642f939b3a44f7199b5537493945c3e045287f@%3Cdev.geode.apache.org%3E","https://lists.apache.org/thread.html/rdcaadaa9a68b31b7d093d76eacfaacf6c7a819f976b595c75ad2d4dc@%3Cdev.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuapr2020.html","https://lists.apache.org/thread.html/r0f3530f7cb510036e497532ffc4e0bd0b882940448cf4e233994b08b@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r3765353ff434fd00d8fa5a44734b3625a06eeb2a3fb468da7dfae134@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r7361bfe84bde9d233f9800c3a96673e7bd81207549ced0236f07a29d@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r7d5e518088e2e778928b02bcd3be3b948b59acefe2f0ebb57ec2ebb0@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r8736185eb921022225a83e56d7285a217fd83f5524bd64a6ca3bf5cc@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r9fb1ee08cf337d16c3364feb0f35a072438c1a956afd7b77859aa090@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r028977b9b9d44a89823639aa3296fb0f0cfdd76b4450df89d3c4fbbf@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r1bc5d673c01cfbb8e4a91914e9748ead3e5f56b61bca54d314c0419b@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r4b1886e82cc98ef38f582fef7d4ea722e3fcf46637cd4674926ba682@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r74f81f93a9b69140fe41e236afa7cbe8dfa75692e7ab31a468fddaa0@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/rab0de39839b4c208dcd73f01e12899dc453361935a816a784548e048@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/reaa8a6674baf2724b1b88a621b0d72d9f7a6f5577c88759842c16eb6@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r0f2d0ae1bad2edb3d4a863d77f3097b5e88cfbdae7b809f4f42d6aad@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r1accbd4f31ad2f40e1661d70a4510a584eb3efd1e32e8660ccf46676@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r2dfd5b331b46d3f90c4dd63a060e9f04300468293874bd7e41af7163@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r4639e821ef9ca6ca10887988f410a60261400a7766560e7a97a22efc@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r6dac0e365d1b2df9a7ffca12b4195181ec14ff0abdf59e1fdb088ce5@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r8cc37a60a5056351377ee5f1258f2a4fdd39822a257838ba6bcc1e88@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/rb4d1fc078f086ec2e98b2693e8b358e58a6a4ef903ceed93a1ee2b18@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r712a6fce928e24e7b6ec30994a7e115a70f1f6e4cf2c2fbf0347ce46@%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/r881fb5a95ab251106fed38f836257276feb026bfe01290e72ff91c2a@%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/ra996b56e1f5ab2fed235a8b91fa0cc3cf34c2e9fee290b7fa4380a0d@%3Ccommits.servicecomb.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1c679c43fa4f7846d748a937955c7921436d1b315445978254442163@%3Ccommits.ambari.apache.org%3E","https://lists.apache.org/thread.html/r1eccdbd7986618a7319ee7a533bd9d9bf6e8678e59dd4cca9b5b2d7a@%3Cissues.ambari.apache.org%3E","https://lists.apache.org/thread.html/r5c95eff679dfc642e9e4ab5ac6d202248a59cb1e9457cfbe8b729ac5@%3Cissues.ambari.apache.org%3E","https://lists.apache.org/thread.html/r8b496b1743d128e6861ee0ed3c3c48cc56c505b38f84fa5baf7ae33a@%3Cdev.ambari.apache.org%3E","https://lists.apache.org/thread.html/r9f13cccb214495e14648d2c9b8f2c6072fd5219e74502dd35ede81e1@%3Cdev.ambari.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://lists.apache.org/thread.html/r27552d2fa10d96f2810c50d16ad1fd1899e37796c81a0c5e7585a02d@%3Cdev.rocketmq.apache.org%3E","https://lists.apache.org/thread.html/r645408661a8df9158f49e337072df39838fa76da629a7e25a20928a6@%3Cdev.rocketmq.apache.org%3E","https://lists.apache.org/thread.html/rc9c7f96f08c8554225dba9050ea5e64bebc129d0d836303143fe3160@%3Cdev.rocketmq.apache.org%3E","https://lists.apache.org/thread.html/rded5291e25a4c4085a6d43cf262e479140198bf4eabb84986e0a1ef3@%3Cdev.rocketmq.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/spring-projects/spring-framework/commit/41f40c6c229d3b4f768718f1ec229d8f0ad76d76","https://security.netapp.com/advisory/ntap-20210917-0006"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8wx2-9q48-vm9r","description":"RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application"},"relatedVulnerabilities":[{"id":"CVE-2020-5398","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.6,"impactScore":10.1,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@pivotal.io","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8,"impactScore":6.1,"exploitabilityScore":1.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-5398","cwe":"CWE-79","type":"Secondary","source":"security@pivotal.io"},{"cve":"CVE-2020-5398","cwe":"CWE-494","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-5398","date":"2026-10-08","epss":0.88768,"percentile":0.99775}],"urls":["https://lists.apache.org/thread.html/r028977b9b9d44a89823639aa3296fb0f0cfdd76b4450df89d3c4fbbf%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r0f2d0ae1bad2edb3d4a863d77f3097b5e88cfbdae7b809f4f42d6aad%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r0f3530f7cb510036e497532ffc4e0bd0b882940448cf4e233994b08b%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r1accbd4f31ad2f40e1661d70a4510a584eb3efd1e32e8660ccf46676%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r1bc5d673c01cfbb8e4a91914e9748ead3e5f56b61bca54d314c0419b%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r1c679c43fa4f7846d748a937955c7921436d1b315445978254442163%40%3Ccommits.ambari.apache.org%3E","https://lists.apache.org/thread.html/r1eccdbd7986618a7319ee7a533bd9d9bf6e8678e59dd4cca9b5b2d7a%40%3Cissues.ambari.apache.org%3E","https://lists.apache.org/thread.html/r27552d2fa10d96f2810c50d16ad1fd1899e37796c81a0c5e7585a02d%40%3Cdev.rocketmq.apache.org%3E","https://lists.apache.org/thread.html/r2dfd5b331b46d3f90c4dd63a060e9f04300468293874bd7e41af7163%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r3765353ff434fd00d8fa5a44734b3625a06eeb2a3fb468da7dfae134%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r4639e821ef9ca6ca10887988f410a60261400a7766560e7a97a22efc%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r4b1886e82cc98ef38f582fef7d4ea722e3fcf46637cd4674926ba682%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r5c95eff679dfc642e9e4ab5ac6d202248a59cb1e9457cfbe8b729ac5%40%3Cissues.ambari.apache.org%3E","https://lists.apache.org/thread.html/r645408661a8df9158f49e337072df39838fa76da629a7e25a20928a6%40%3Cdev.rocketmq.apache.org%3E","https://lists.apache.org/thread.html/r6dac0e365d1b2df9a7ffca12b4195181ec14ff0abdf59e1fdb088ce5%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r712a6fce928e24e7b6ec30994a7e115a70f1f6e4cf2c2fbf0347ce46%40%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/r7361bfe84bde9d233f9800c3a96673e7bd81207549ced0236f07a29d%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r74f81f93a9b69140fe41e236afa7cbe8dfa75692e7ab31a468fddaa0%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r7d5e518088e2e778928b02bcd3be3b948b59acefe2f0ebb57ec2ebb0%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r8736185eb921022225a83e56d7285a217fd83f5524bd64a6ca3bf5cc%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r881fb5a95ab251106fed38f836257276feb026bfe01290e72ff91c2a%40%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/r8b496b1743d128e6861ee0ed3c3c48cc56c505b38f84fa5baf7ae33a%40%3Cdev.ambari.apache.org%3E","https://lists.apache.org/thread.html/r8cc37a60a5056351377ee5f1258f2a4fdd39822a257838ba6bcc1e88%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r9f13cccb214495e14648d2c9b8f2c6072fd5219e74502dd35ede81e1%40%3Cdev.ambari.apache.org%3E","https://lists.apache.org/thread.html/r9fb1ee08cf337d16c3364feb0f35a072438c1a956afd7b77859aa090%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/ra996b56e1f5ab2fed235a8b91fa0cc3cf34c2e9fee290b7fa4380a0d%40%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/rab0de39839b4c208dcd73f01e12899dc453361935a816a784548e048%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/rb4d1fc078f086ec2e98b2693e8b358e58a6a4ef903ceed93a1ee2b18%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/rc05acaacad089613e9642f939b3a44f7199b5537493945c3e045287f%40%3Cdev.geode.apache.org%3E","https://lists.apache.org/thread.html/rc9c7f96f08c8554225dba9050ea5e64bebc129d0d836303143fe3160%40%3Cdev.rocketmq.apache.org%3E","https://lists.apache.org/thread.html/rdcaadaa9a68b31b7d093d76eacfaacf6c7a819f976b595c75ad2d4dc%40%3Cdev.geode.apache.org%3E","https://lists.apache.org/thread.html/rded5291e25a4c4085a6d43cf262e479140198bf4eabb84986e0a1ef3%40%3Cdev.rocketmq.apache.org%3E","https://lists.apache.org/thread.html/reaa8a6674baf2724b1b88a621b0d72d9f7a6f5577c88759842c16eb6%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/rf8dc72b974ee74f17bce661ea7d124e733a1f4c4f236354ac0cf48e8%40%3Ccommits.camel.apache.org%3E","https://pivotal.io/security/cve-2020-5398","https://security.netapp.com/advisory/ntap-20210917-0006/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-5398","description":"In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a \"Content-Disposition\" header in the response where the filename attribute is derived from user supplied input."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.13"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3711","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3711","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.13"],"available":[{"date":"2021-08-24","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3711","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3711","date":"2026-10-08","epss":0.87816,"percentile":0.9976}],"risk":65.862,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3711"},"relatedVulnerabilities":[{"id":"CVE-2021-3711","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3711","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3711","date":"2026-10-08","epss":0.87816,"percentile":0.9976}],"urls":["http://www.openwall.com/lists/oss-security/2021/08/26/2","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=59f5e75f3bced8fc0e130d72a3f582cf7b480b46","https://lists.apache.org/thread.html/r18995de860f0e63635f3008fd2a6aca82394249476d21691e7c59c9e%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rad5d9f83f0d11fb3f8bb148d179b8a9ad7c6a17f18d70e5805a713d1%40%3Cdev.tomcat.apache.org%3E","https://security.gentoo.org/glsa/202209-02","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20210827-0010/","https://security.netapp.com/advisory/ntap-20211022-0003/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-4963","https://www.openssl.org/news/secadv/20210824.txt","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-16","https://www.tenable.com/security/tns-2022-02"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3711","description":"In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the \"out\" parameter can be NULL and, on exit, the \"outlen\" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the \"out\" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen data to overflow the buffer by up to a maximum of 62 bytes altering the contents of other data held after the buffer, possibly changing application behaviour or causing the application to crash. The location of the buffer is application dependent but is typically heap allocated. Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k)."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-3711","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3711","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.13"],"available":[{"date":"2021-08-24","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3711","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3711","date":"2026-10-08","epss":0.87816,"percentile":0.9976}],"risk":65.862,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3711"},"relatedVulnerabilities":[{"id":"CVE-2021-3711","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3711","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3711","date":"2026-10-08","epss":0.87816,"percentile":0.9976}],"urls":["http://www.openwall.com/lists/oss-security/2021/08/26/2","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=59f5e75f3bced8fc0e130d72a3f582cf7b480b46","https://lists.apache.org/thread.html/r18995de860f0e63635f3008fd2a6aca82394249476d21691e7c59c9e%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rad5d9f83f0d11fb3f8bb148d179b8a9ad7c6a17f18d70e5805a713d1%40%3Cdev.tomcat.apache.org%3E","https://security.gentoo.org/glsa/202209-02","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20210827-0010/","https://security.netapp.com/advisory/ntap-20211022-0003/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-4963","https://www.openssl.org/news/secadv/20210824.txt","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-16","https://www.tenable.com/security/tns-2022-02"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3711","description":"In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the \"out\" parameter can be NULL and, on exit, the \"outlen\" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the \"out\" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen data to overflow the buffer by up to a maximum of 62 bytes altering the contents of other data held after the buffer, possibly changing application behaviour or causing the application to crash. The location of the buffer is application dependent but is typically heap allocated. Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k)."}]},{"artifact":{"id":"9cf2e4f1f15b1d30","cpes":["cpe:2.3:a:apache:tomcat-embed-websocket:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_websocket:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-websocket","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-websocket-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-websocket","archiveDigests":[{"value":"ea5302e378f1449d4e5dda79e8d810c1e7931f91","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-websocket-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.57"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m7jv-hq7h-mq7c","versionConstraint":">=8.5.0,<8.5.57 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-websocket","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-m7jv-hq7h-mq7c","fix":{"state":"fixed","versions":["8.5.57"],"available":[{"date":"2026-06-11","kind":"first-observed","version":"8.5.57"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-13935","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-13935","date":"2026-10-08","epss":0.86608,"percentile":0.99737}],"risk":64.95599999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-13935","https://kc.mcafee.com/corporate/index?page=content&id=SB10332","https://lists.apache.org/thread.html/r4e5d3c09f4dd2923191e972408b40fb8b42dbff0bc7904d44b651e50@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd48c72bd3255bda87564d4da3791517c074d94f8a701f93b85752651%40%3Cannounce.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/07/msg00017.html","https://www.debian.org/security/2020/dsa-4727","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://github.com/apache/tomcat/commit/12d715676038efbf9c728af10163f8277fc019d5","https://github.com/apache/tomcat/commit/1c1c77b0efb667cea80b532440b44cea1dc427c3","https://github.com/apache/tomcat/commit/40fa74c74822711ab878079d0a69f7357926723d","https://github.com/apache/tomcat/commit/4c04982870d6e730c38e21e58fb653b7cf723784","https://github.com/apache/tomcat/commit/f9f75c14678b68633f79030ddf4ff827f014cc84","https://usn.ubuntu.com/4596-1","https://usn.ubuntu.com/4448-1","https://security.netapp.com/advisory/ntap-20200724-0003","https://tomcat.apache.org/security-9.html","https://tomcat.apache.org/security-8.html","https://tomcat.apache.org/security-7.html","https://tomcat.apache.org/security-10.html","https://lists.apache.org/thread.html/r4e5d3c09f4dd2923191e972408b40fb8b42dbff0bc7904d44b651e50%40%3Cusers.tomcat.apache.org%3E"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m7jv-hq7h-mq7c","description":"Infinite Loop in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2020-13935","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-13935","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-13935","date":"2026-10-08","epss":0.86608,"percentile":0.99737}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.html","https://kc.mcafee.com/corporate/index?page=content&id=SB10332","https://lists.apache.org/thread.html/r4e5d3c09f4dd2923191e972408b40fb8b42dbff0bc7904d44b651e50%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd48c72bd3255bda87564d4da3791517c074d94f8a701f93b85752651%40%3Cannounce.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/07/msg00017.html","https://security.netapp.com/advisory/ntap-20200724-0003/","https://usn.ubuntu.com/4448-1/","https://usn.ubuntu.com/4596-1/","https://www.debian.org/security/2020/dsa-4727","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-13935","description":"The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.94"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qppj-fm5r-hxr3","versionConstraint":">=8.5.0,<8.5.94 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qppj-fm5r-hxr3","fix":{"state":"fixed","versions":["8.5.94"],"available":[{"date":"2023-12-22","kind":"first-observed","version":"8.5.94"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:H","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:A","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-44487","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-44487","date":"2026-10-08","epss":0.99999,"percentile":0.99998}],"risk":58.275,"urls":["https://github.com/apple/swift-nio-http2/security/advisories/GHSA-qppj-fm5r-hxr3","https://nvd.nist.gov/vuln/detail/CVE-2023-44487","https://github.com/alibaba/tengine/issues/1872","https://github.com/caddyserver/caddy/issues/5877","https://github.com/eclipse/jetty.project/issues/10679","https://github.com/haproxy/haproxy/issues/2312","https://github.com/hyperium/hyper/issues/3337","https://github.com/envoyproxy/envoy/pull/30055","https://github.com/grpc/grpc-go/pull/6703","https://github.com/nghttp2/nghttp2/pull/1961","https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61","https://bugzilla.proxmox.com/show_bug.cgi?id=4988","https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9","https://chaos.social/@icing/111210915918780532","https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack","https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764","https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2","https://github.com/bcdannyboy/CVE-2023-44487","https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244","https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0","https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html","https://my.f5.com/manage/s/article/K000137106","https://news.ycombinator.com/item?id=37830987","https://news.ycombinator.com/item?id=37830998","https://news.ycombinator.com/item?id=37831062","https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack","https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf","https://github.com/dotnet/announcements/issues/277","https://github.com/golang/go/issues/63417","https://github.com/apache/trafficserver/pull/10564","https://github.com/facebook/proxygen/pull/466","https://github.com/h2o/h2o/pull/3291","https://github.com/microsoft/CBL-Mariner/pull/6381","https://github.com/nodejs/node/pull/50121","https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve","https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088","https://github.com/advisories/GHSA-vx74-f528-fxqg","https://github.com/micrictor/http2-rst-stream","https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo","https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487","https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected","https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14","https://www.openwall.com/lists/oss-security/2023/10/10/6","https://github.com/opensearch-project/data-prepper/issues/3474","https://github.com/kubernetes/kubernetes/pull/121120","https://github.com/advisories/GHSA-xpw8-rcwv-8f8p","https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73","https://github.com/oqtane/oqtane.framework/discussions/3367","https://netty.io/news/2023/10/10/4-1-100-Final.html","https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487","https://github.com/Azure/AKS/issues/3947","https://github.com/akka/akka-http/issues/4323","https://github.com/apache/apisix/issues/10320","https://github.com/etcd-io/etcd/issues/16740","https://github.com/junkurihara/rust-rpxy/issues/97","https://github.com/kazu-yamamoto/http2/issues/93","https://github.com/ninenines/cowboy/issues/1615","https://github.com/openresty/openresty/issues/930","https://github.com/tempesta-tech/tempesta/issues/1986","https://github.com/varnishcache/varnish-cache/issues/3996","https://github.com/apache/httpd-site/pull/10","https://github.com/line/armeria/pull/5232","https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632","https://github.com/projectcontour/contour/pull/5826","https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1","https://access.redhat.com/security/cve/cve-2023-44487","https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack","https://bugzilla.redhat.com/show_bug.cgi?id=2242803","https://bugzilla.suse.com/show_bug.cgi?id=1216123","https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125","https://github.com/Kong/kong/discussions/11741","https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113","https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487","https://github.com/caddyserver/caddy/releases/tag/v2.7.5","https://go.dev/cl/534215","https://go.dev/cl/534235","https://go.dev/issue/63417","https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo/m/UDd7VKQuAAAJ","https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html","https://news.ycombinator.com/item?id=37837043","https://security.paloaltonetworks.com/CVE-2023-44487","https://ubuntu.com/security/CVE-2023-44487","https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487","https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event","https://www.debian.org/security/2023/dsa-5521","https://www.debian.org/security/2023/dsa-5522","http://www.openwall.com/lists/oss-security/2023/10/13/4","http://www.openwall.com/lists/oss-security/2023/10/13/9","https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html","https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html","https://github.com/grpc/grpc-go/releases","https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html","https://www.debian.org/security/2023/dsa-5540","http://www.openwall.com/lists/oss-security/2023/10/18/4","http://www.openwall.com/lists/oss-security/2023/10/18/8","http://www.openwall.com/lists/oss-security/2023/10/19/6","http://www.openwall.com/lists/oss-security/2023/10/20/8","https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715","https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html","https://www.debian.org/security/2023/dsa-5549","https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html","https://security.gentoo.org/glsa/202311-09","https://www.debian.org/security/2023/dsa-5558","https://www.debian.org/security/2023/dsa-5570","https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.0-M12","https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.94","https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.81","https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size","https://aws.amazon.com/security/security-bulletins/AWS-2023-011","https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack","https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack","https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty","https://blog.vespa.ai/cve-2023-44487","https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps","https://istio.io/latest/news/security/istio-security-2023-004","https://linkerd.io/2023/10/12/linkerd-cve-2023-44487","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4","https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2","https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response","https://security.netapp.com/advisory/ntap-20231016-0001","https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records","https://www.eclipse.org/lists/jetty-announce/msg00181.html","https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487","https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products","https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday","https://github.com/akka/akka-http/pull/4325","https://github.com/akka/akka-http/pull/4324","https://akka.io/security/akka-http-cve-2023-44487.html","https://security.netapp.com/advisory/ntap-20240426-0007","https://security.netapp.com/advisory/ntap-20240621-0006","https://security.netapp.com/advisory/ntap-20240621-0007","https://github.com/apache/tomcat/commit/944332bb15bd2f3bf76ec2caeb1ff0a58a3bc628","https://www.vicarius.io/vsociety/posts/rapid-reset-cve-2023-44487-dos-in-http2-understanding-the-root-cause","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX","https://github.com/grpc/grpc/releases/tag/v1.59.2","http://www.openwall.com/lists/oss-security/2023/10/10/6","http://www.openwall.com/lists/oss-security/2023/10/10/7","https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44487","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-341067.html","https://cert-portal.siemens.com/productcert/html/ssa-784301.html","https://cert-portal.siemens.com/productcert/html/ssa-832273.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html","http://www.openwall.com/lists/oss-security/2025/08/13/6"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qppj-fm5r-hxr3","description":"HTTP/2 Stream Cancellation Attack","knownExploited":[{"cve":"CVE-2023-44487","cwes":["CWE-400"],"urls":["https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/","https://nvd.nist.gov/vuln/detail/CVE-2023-44487"],"notes":"This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487","dueDate":"2023-10-31","product":"HTTP/2","dateAdded":"2023-10-10","vendorProject":"IETF","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2023-44487","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-44487","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-44487","date":"2026-10-08","epss":0.99999,"percentile":0.99998}],"urls":["http://www.openwall.com/lists/oss-security/2023/10/10/6","http://www.openwall.com/lists/oss-security/2023/10/10/7","http://www.openwall.com/lists/oss-security/2023/10/13/4","http://www.openwall.com/lists/oss-security/2023/10/13/9","http://www.openwall.com/lists/oss-security/2023/10/18/4","http://www.openwall.com/lists/oss-security/2023/10/18/8","http://www.openwall.com/lists/oss-security/2023/10/19/6","http://www.openwall.com/lists/oss-security/2023/10/20/8","https://access.redhat.com/security/cve/cve-2023-44487","https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/","https://aws.amazon.com/security/security-bulletins/AWS-2023-011/","https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/","https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/","https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/","https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack","https://blog.vespa.ai/cve-2023-44487/","https://bugzilla.proxmox.com/show_bug.cgi?id=4988","https://bugzilla.redhat.com/show_bug.cgi?id=2242803","https://bugzilla.suse.com/show_bug.cgi?id=1216123","https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9","https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/","https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack","https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125","https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715","https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve","https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764","https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088","https://github.com/Azure/AKS/issues/3947","https://github.com/Kong/kong/discussions/11741","https://github.com/advisories/GHSA-qppj-fm5r-hxr3","https://github.com/advisories/GHSA-vx74-f528-fxqg","https://github.com/advisories/GHSA-xpw8-rcwv-8f8p","https://github.com/akka/akka-http/issues/4323","https://github.com/alibaba/tengine/issues/1872","https://github.com/apache/apisix/issues/10320","https://github.com/apache/httpd-site/pull/10","https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113","https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2","https://github.com/apache/trafficserver/pull/10564","https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487","https://github.com/bcdannyboy/CVE-2023-44487","https://github.com/caddyserver/caddy/issues/5877","https://github.com/caddyserver/caddy/releases/tag/v2.7.5","https://github.com/dotnet/announcements/issues/277","https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73","https://github.com/eclipse/jetty.project/issues/10679","https://github.com/envoyproxy/envoy/pull/30055","https://github.com/etcd-io/etcd/issues/16740","https://github.com/facebook/proxygen/pull/466","https://github.com/golang/go/issues/63417","https://github.com/grpc/grpc-go/pull/6703","https://github.com/grpc/grpc/releases/tag/v1.59.2","https://github.com/h2o/h2o/pull/3291","https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf","https://github.com/haproxy/haproxy/issues/2312","https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244","https://github.com/junkurihara/rust-rpxy/issues/97","https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1","https://github.com/kazu-yamamoto/http2/issues/93","https://github.com/kubernetes/kubernetes/pull/121120","https://github.com/line/armeria/pull/5232","https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632","https://github.com/micrictor/http2-rst-stream","https://github.com/microsoft/CBL-Mariner/pull/6381","https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61","https://github.com/nghttp2/nghttp2/pull/1961","https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0","https://github.com/ninenines/cowboy/issues/1615","https://github.com/nodejs/node/pull/50121","https://github.com/openresty/openresty/issues/930","https://github.com/opensearch-project/data-prepper/issues/3474","https://github.com/oqtane/oqtane.framework/discussions/3367","https://github.com/projectcontour/contour/pull/5826","https://github.com/tempesta-tech/tempesta/issues/1986","https://github.com/varnishcache/varnish-cache/issues/3996","https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo","https://istio.io/latest/news/security/istio-security-2023-004/","https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/","https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q","https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html","https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html","https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/","https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html","https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html","https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html","https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487","https://my.f5.com/manage/s/article/K000137106","https://netty.io/news/2023/10/10/4-1-100-Final.html","https://news.ycombinator.com/item?id=37830987","https://news.ycombinator.com/item?id=37830998","https://news.ycombinator.com/item?id=37831062","https://news.ycombinator.com/item?id=37837043","https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/","https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected","https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ","https://security.gentoo.org/glsa/202311-09","https://security.netapp.com/advisory/ntap-20231016-0001/","https://security.netapp.com/advisory/ntap-20240426-0007/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://security.netapp.com/advisory/ntap-20240621-0007/","https://security.paloaltonetworks.com/CVE-2023-44487","https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14","https://ubuntu.com/security/CVE-2023-44487","https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/","https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487","https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event","https://www.debian.org/security/2023/dsa-5521","https://www.debian.org/security/2023/dsa-5522","https://www.debian.org/security/2023/dsa-5540","https://www.debian.org/security/2023/dsa-5549","https://www.debian.org/security/2023/dsa-5558","https://www.debian.org/security/2023/dsa-5570","https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487","https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/","https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/","https://www.openwall.com/lists/oss-security/2023/10/10/6","https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack","https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/","http://www.openwall.com/lists/oss-security/2025/08/13/6","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/","https://www.vicarius.io/vsociety/posts/rapid-reset-cve-2023-44487-dos-in-http2-understanding-the-root-cause","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-341067.html","https://cert-portal.siemens.com/productcert/html/ssa-784301.html","https://cert-portal.siemens.com/productcert/html/ssa-832273.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44487","https://github.com/envoyproxy/envoy/security/advisories/GHSA-jhv4-f7mr-xx76","https://github.com/kubernetes/ingress-nginx/blob/4b5c5efe2508dc915a48c54de7f23912ff2ec695/changelog/controller-1.9.3.md?plain=1#L15","https://varnish-cache.org/releases/rel6.0.12.html#rel6-0-12","https://varnish-cache.org/releases/rel7.3.1.html#rel7-3-1","https://varnish-cache.org/releases/rel7.4.2.html#rel7-4-2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-44487","description":"The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.","knownExploited":[{"cve":"CVE-2023-44487","cwes":["CWE-400"],"urls":["https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/","https://nvd.nist.gov/vuln/detail/CVE-2023-44487"],"notes":"This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487","dueDate":"2023-10-31","product":"HTTP/2","dateAdded":"2023-10-10","vendorProject":"IETF","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-0778","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-0778","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.15"],"available":[{"date":"2022-03-15","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-0778","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-0778","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-0778","date":"2026-10-08","epss":0.73188,"percentile":0.99448}],"risk":54.891,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-0778"},"relatedVulnerabilities":[{"id":"CVE-2022-0778","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0778","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-0778","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-0778","date":"2026-10-08","epss":0.73188,"percentile":0.99448}],"urls":["http://packetstormsecurity.com/files/167344/OpenSSL-1.0.2-1.1.1-3.0-BN_mod_sqrt-Infinite-Loop.html","http://seclists.org/fulldisclosure/2022/May/33","http://seclists.org/fulldisclosure/2022/May/35","http://seclists.org/fulldisclosure/2022/May/38","https://cert-portal.siemens.com/productcert/pdf/ssa-712929.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=3118eb64934499d93db3230748a452351d1d9a65","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=380085481c64de749a6dd25cdf0bcf4360b30f83","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a466912611aa6cbdf550cd10601390e587451246","https://lists.debian.org/debian-lts-announce/2022/03/msg00023.html","https://lists.debian.org/debian-lts-announce/2022/03/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GDB3GQVJPXJE7X5C5JN6JAA4XUDWD6E6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6K3PR542DXWLEFFMFIDMME4CWMHJRMG/","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0002","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20220321-0002/","https://security.netapp.com/advisory/ntap-20220429-0005/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://support.apple.com/kb/HT213255","https://support.apple.com/kb/HT213256","https://support.apple.com/kb/HT213257","https://www.debian.org/security/2022/dsa-5103","https://www.openssl.org/news/secadv/20220315.txt","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.tenable.com/security/tns-2022-06","https://www.tenable.com/security/tns-2022-07","https://www.tenable.com/security/tns-2022-08","https://www.tenable.com/security/tns-2022-09","https://cert-portal.siemens.com/productcert/html/ssa-019200.html","https://cert-portal.siemens.com/productcert/html/ssa-028723.html","https://cert-portal.siemens.com/productcert/html/ssa-108696.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-712929.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0778","description":"The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc)."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-0778","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-0778","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.15"],"available":[{"date":"2022-03-15","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-0778","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-0778","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-0778","date":"2026-10-08","epss":0.73188,"percentile":0.99448}],"risk":54.891,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-0778"},"relatedVulnerabilities":[{"id":"CVE-2022-0778","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0778","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-0778","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-0778","date":"2026-10-08","epss":0.73188,"percentile":0.99448}],"urls":["http://packetstormsecurity.com/files/167344/OpenSSL-1.0.2-1.1.1-3.0-BN_mod_sqrt-Infinite-Loop.html","http://seclists.org/fulldisclosure/2022/May/33","http://seclists.org/fulldisclosure/2022/May/35","http://seclists.org/fulldisclosure/2022/May/38","https://cert-portal.siemens.com/productcert/pdf/ssa-712929.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=3118eb64934499d93db3230748a452351d1d9a65","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=380085481c64de749a6dd25cdf0bcf4360b30f83","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a466912611aa6cbdf550cd10601390e587451246","https://lists.debian.org/debian-lts-announce/2022/03/msg00023.html","https://lists.debian.org/debian-lts-announce/2022/03/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GDB3GQVJPXJE7X5C5JN6JAA4XUDWD6E6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6K3PR542DXWLEFFMFIDMME4CWMHJRMG/","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0002","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20220321-0002/","https://security.netapp.com/advisory/ntap-20220429-0005/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://support.apple.com/kb/HT213255","https://support.apple.com/kb/HT213256","https://support.apple.com/kb/HT213257","https://www.debian.org/security/2022/dsa-5103","https://www.openssl.org/news/secadv/20220315.txt","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.tenable.com/security/tns-2022-06","https://www.tenable.com/security/tns-2022-07","https://www.tenable.com/security/tns-2022-08","https://www.tenable.com/security/tns-2022-09","https://cert-portal.siemens.com/productcert/html/ssa-019200.html","https://cert-portal.siemens.com/productcert/html/ssa-028723.html","https://cert-portal.siemens.com/productcert/html/ssa-108696.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-712929.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0778","description":"The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc)."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.41"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4hg-rmq2-52q9","versionConstraint":">=8.5.0,<8.5.41 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4hg-rmq2-52q9","fix":{"state":"fixed","versions":["8.5.41"],"available":[{"date":"2024-03-12","kind":"first-observed","version":"8.5.41"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-10072","cwe":"CWE-667","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-10072","date":"2026-10-08","epss":0.72988,"percentile":0.99444}],"risk":54.74099999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-10072","https://lists.apache.org/thread.html/df1a2c1b87c8a6c500ecdbbaf134c7f1491c8d79d98b48c6b9f0fa6a@%3Cannounce.tomcat.apache.org%3E","https://access.redhat.com/errata/RHSA-2019:3929","https://access.redhat.com/errata/RHSA-2019:3931","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a@%3Cdev.tomcat.apache.org%3E","https://support.f5.com/csp/article/K17321505","https://www.debian.org/security/2020/dsa-4680","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.synology.com/security/advisory/Synology_SA_19_29","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://lists.apache.org/thread.html/df1a2c1b87c8a6c500ecdbbaf134c7f1491c8d79d98b48c6b9f0fa6a%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E","https://web.archive.org/web/20200227033743/http://www.securityfocus.com/bid/108874","https://github.com/apache/tomcat/commit/0bcd69c9dd8ae0ff424f2cd46de51583510b7f35","https://github.com/apache/tomcat/commit/7f748eb6bfaba5207c89dbd7d5adf50fae847145","https://github.com/apache/tomcat/commit/8d14c6f21d29768a39be4b6b9517060dc6606758","https://github.com/apache/tomcat/commit/ada725a50a60867af3422c8e612aecaeea856a9a","https://tomcat.apache.org/security-8.html","https://tomcat.apache.org/security-9.html","https://usn.ubuntu.com/4128-1","https://usn.ubuntu.com/4128-2","https://security.netapp.com/advisory/ntap-20190625-0002"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4hg-rmq2-52q9","description":"Improper Locking in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2019-10072","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-10072","cwe":"CWE-667","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-10072","date":"2026-10-08","epss":0.72988,"percentile":0.99444}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.html","http://www.securityfocus.com/bid/108874","https://access.redhat.com/errata/RHSA-2019:3929","https://access.redhat.com/errata/RHSA-2019:3931","https://lists.apache.org/thread.html/df1a2c1b87c8a6c500ecdbbaf134c7f1491c8d79d98b48c6b9f0fa6a%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E","https://security.netapp.com/advisory/ntap-20190625-0002/","https://support.f5.com/csp/article/K17321505","https://usn.ubuntu.com/4128-1/","https://usn.ubuntu.com/4128-2/","https://www.debian.org/security/2020/dsa-4680","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.synology.com/security/advisory/Synology_SA_19_29"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-10072","description":"The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.38"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qcxh-w3j9-58qr","versionConstraint":">=8.0.0,<8.5.38 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qcxh-w3j9-58qr","fix":{"state":"fixed","versions":["8.5.38"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"8.5.38"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0199","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0199","date":"2026-10-08","epss":0.72855,"percentile":0.9944}],"risk":54.64125,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0199","https://access.redhat.com/errata/RHSA-2019:3929","https://access.redhat.com/errata/RHSA-2019:3931","https://lists.apache.org/thread.html/158ab719cf60448ddbb074798f09152fdb572fc8f781e70a56118d1a@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/4c438fa4c78cb1ce8979077f668ab7145baf83e7c59f2faf7eccf094@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/7bb193bc68b28d21ff1c726fd38bea164deb6333b59eec2eb3661da6@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/9fe25f98bac6d66f8a663a15c37a98bc2d8f8bbed1d408791a3e4067@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/a7a201bd23e67fd3326c9b22b814dd0537d3270b3b54a768e2e7ef50@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/ac0185ce240a711b542a55bccf9349ab0c2f343d70cf7835e08fabc9@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/cf4eb2bd2083cebb3602a293c653f9a7faa96c86f672c876f25b37ef@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/dddb3590bac28fbe89f69f5ccbe26283d014ddc691abdd042de14600@%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/df1a2c1b87c8a6c500ecdbbaf134c7f1491c8d79d98b48c6b9f0fa6a@%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/e1b0b273b6e8ddcc72c9023bc2394b1276fc72664144bf21d0a87995@%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/e56886e1bac9319ecce81b3612dd7a1a43174a3a741a1c805e16880e@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/e87733036e8c84ea648cdcdca3098f3c8a897e2652c33062b2b1535c@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a@%3Cdev.tomcat.apache.org%3E","https://seclists.org/bugtraq/2019/Dec/43","https://support.f5.com/csp/article/K17321505","https://www.debian.org/security/2019/dsa-4596","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00090.html","http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00013.html","http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00054.html","https://lists.apache.org/thread.html/158ab719cf60448ddbb074798f09152fdb572fc8f781e70a56118d1a%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/4c438fa4c78cb1ce8979077f668ab7145baf83e7c59f2faf7eccf094%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/7bb193bc68b28d21ff1c726fd38bea164deb6333b59eec2eb3661da6%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/9fe25f98bac6d66f8a663a15c37a98bc2d8f8bbed1d408791a3e4067%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/a7a201bd23e67fd3326c9b22b814dd0537d3270b3b54a768e2e7ef50%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/ac0185ce240a711b542a55bccf9349ab0c2f343d70cf7835e08fabc9%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/cf4eb2bd2083cebb3602a293c653f9a7faa96c86f672c876f25b37ef%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/dddb3590bac28fbe89f69f5ccbe26283d014ddc691abdd042de14600%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/df1a2c1b87c8a6c500ecdbbaf134c7f1491c8d79d98b48c6b9f0fa6a%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/e1b0b273b6e8ddcc72c9023bc2394b1276fc72664144bf21d0a87995%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/e56886e1bac9319ecce81b3612dd7a1a43174a3a741a1c805e16880e%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/e87733036e8c84ea648cdcdca3098f3c8a897e2652c33062b2b1535c%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E","https://web.archive.org/web/20200227030041/http://www.securityfocus.com/bid/107674","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NPHQEL5AQ6LZSZD2Y6TYZ4RC3WI7NXJ3","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQTZ5BJ5F4KV6N53SGNKSW3UY5DBIQ46","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NPHQEL5AQ6LZSZD2Y6TYZ4RC3WI7NXJ3","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZQTZ5BJ5F4KV6N53SGNKSW3UY5DBIQ46","https://security.netapp.com/advisory/ntap-20190419-0001"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qcxh-w3j9-58qr","description":"Apache Tomcat Denial of Service vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2019-0199","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0199","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0199","date":"2026-10-08","epss":0.72855,"percentile":0.9944}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00090.html","http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00013.html","http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00054.html","http://www.securityfocus.com/bid/107674","https://access.redhat.com/errata/RHSA-2019:3929","https://access.redhat.com/errata/RHSA-2019:3931","https://lists.apache.org/thread.html/158ab719cf60448ddbb074798f09152fdb572fc8f781e70a56118d1a%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/4c438fa4c78cb1ce8979077f668ab7145baf83e7c59f2faf7eccf094%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/7bb193bc68b28d21ff1c726fd38bea164deb6333b59eec2eb3661da6%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/9fe25f98bac6d66f8a663a15c37a98bc2d8f8bbed1d408791a3e4067%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/a7a201bd23e67fd3326c9b22b814dd0537d3270b3b54a768e2e7ef50%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/ac0185ce240a711b542a55bccf9349ab0c2f343d70cf7835e08fabc9%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/cf4eb2bd2083cebb3602a293c653f9a7faa96c86f672c876f25b37ef%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/dddb3590bac28fbe89f69f5ccbe26283d014ddc691abdd042de14600%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/df1a2c1b87c8a6c500ecdbbaf134c7f1491c8d79d98b48c6b9f0fa6a%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/e1b0b273b6e8ddcc72c9023bc2394b1276fc72664144bf21d0a87995%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/e56886e1bac9319ecce81b3612dd7a1a43174a3a741a1c805e16880e%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/e87733036e8c84ea648cdcdca3098f3c8a897e2652c33062b2b1535c%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NPHQEL5AQ6LZSZD2Y6TYZ4RC3WI7NXJ3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQTZ5BJ5F4KV6N53SGNKSW3UY5DBIQ46/","https://seclists.org/bugtraq/2019/Dec/43","https://security.netapp.com/advisory/ntap-20190419-0001/","https://support.f5.com/csp/article/K17321505","https://www.debian.org/security/2019/dsa-4596","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0199","description":"The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open for requests that utilised the Servlet API's blocking I/O, clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS."}]},{"artifact":{"id":"1aef213d2b0dcd29","cpes":["cpe:2.3:a:libfreetype6:libfreetype6:2.8.1-2ubuntu2:*:*:*:*:*:*:*"],"name":"libfreetype6","purl":"pkg:deb/ubuntu/libfreetype6@2.8.1-2ubuntu2?arch=amd64&distro=ubuntu-18.04&upstream=freetype","type":"deb","version":"2.8.1-2ubuntu2","language":"","licenses":["BSD-2-Clause","BSD-3-Clause","Catharon-OSL","FTL","GPL-2","GPL-2+","GZip","OpenGroup-BSD-like"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfreetype6/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libfreetype6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"freetype"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-27363","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"freetype","version":"2.8.1-2ubuntu2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2025-27363","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-27363","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-27363","date":"2026-10-08","epss":0.27775,"percentile":0.98048}],"risk":52.5,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-27363","knownExploited":[{"cve":"CVE-2025-27363","cwes":["CWE-787"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-27363"],"notes":"This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://source.android.com/docs/security/bulletin/2025-05-01","dueDate":"2025-05-27","product":"FreeType","dateAdded":"2025-05-06","vendorProject":"FreeType","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2025-27363","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-assign@fb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-27363","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-27363","date":"2026-10-08","epss":0.27775,"percentile":0.98048}],"urls":["https://www.facebook.com/security/advisories/cve-2025-27363","http://www.openwall.com/lists/oss-security/2025/03/13/1","http://www.openwall.com/lists/oss-security/2025/03/13/11","http://www.openwall.com/lists/oss-security/2025/03/13/12","http://www.openwall.com/lists/oss-security/2025/03/13/2","http://www.openwall.com/lists/oss-security/2025/03/13/3","http://www.openwall.com/lists/oss-security/2025/03/13/8","http://www.openwall.com/lists/oss-security/2025/03/14/1","http://www.openwall.com/lists/oss-security/2025/03/14/2","http://www.openwall.com/lists/oss-security/2025/03/14/3","http://www.openwall.com/lists/oss-security/2025/03/14/4","http://www.openwall.com/lists/oss-security/2025/05/06/3","http://www.openwall.com/lists/oss-security/2026/04/16/5","http://www.openwall.com/lists/oss-security/2026/04/19/3","https://lists.debian.org/debian-lts-announce/2025/03/msg00030.html","https://source.android.com/docs/security/bulletin/2025-05-01","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-27363"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-27363","description":"An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.","knownExploited":[{"cve":"CVE-2025-27363","cwes":["CWE-787"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-27363"],"notes":"This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://source.android.com/docs/security/bulletin/2025-05-01","dueDate":"2025-05-27","product":"FreeType","dateAdded":"2025-05-06","vendorProject":"FreeType","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wmwf-9ccg-fff5","versionConstraint":">=8.5.6,<=8.5.100 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wmwf-9ccg-fff5","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55752","cwe":"CWE-23","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-55752","date":"2026-10-08","epss":0.64413,"percentile":0.99219}],"risk":48.631815,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-55752","https://lists.apache.org/thread/n05kjcwyj1s45ovs8ll1qrrojhfb1tog","https://github.com/apache/tomcat/commit/130d36d8492ef9e4eb22952c17c92423cb35fd06","https://github.com/apache/tomcat/commit/b5042622b8b78340ae65403c55dcb9c7416924df","https://github.com/apache/tomcat/commit/fec06c610ed7466b401e29cc567a58aee5ed826a","https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.45","https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.11","https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.109","http://www.openwall.com/lists/oss-security/2025/10/27/4","https://www.vicarius.io/vsociety/posts/cve-2025-55752-detect-apache-tomcat-vulnerability","https://www.vicarius.io/vsociety/posts/cve-2025-55752-mitigate-apache-tomcat-vulnerability","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wmwf-9ccg-fff5","description":"Apache Tomcat Vulnerable to Relative Path Traversal"},"relatedVulnerabilities":[{"id":"CVE-2025-55752","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55752","cwe":"CWE-23","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-55752","date":"2026-10-08","epss":0.64413,"percentile":0.99219}],"urls":["https://lists.apache.org/thread/n05kjcwyj1s45ovs8ll1qrrojhfb1tog","http://www.openwall.com/lists/oss-security/2025/10/27/4","https://www.vicarius.io/vsociety/posts/cve-2025-55752-detect-apache-tomcat-vulnerability","https://www.vicarius.io/vsociety/posts/cve-2025-55752-mitigate-apache-tomcat-vulnerability","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55752","description":"Relative Path Traversal vulnerability in Apache Tomcat.\n\nThe fix for bug 60013 introduced a regression where the       rewritten URL was normalized before it was decoded. This introduced the       possibility that, for rewrite rules that rewrite query parameters to the       URL, an attacker could manipulate the request URI to bypass security       constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108.\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected.\nUsers are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.19"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-2068","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-2068","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.19"],"available":[{"date":"2022-06-21","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.19"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-2068","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-2068","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-2068","date":"2026-10-08","epss":0.95404,"percentile":0.99869}],"risk":47.702,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-2068"},"relatedVulnerabilities":[{"id":"CVE-2022-2068","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-2068","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-2068","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-2068","date":"2026-10-08","epss":0.95404,"percentile":0.99869}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2c9c35870601b4a44d86ddbf512b38df38285cfa","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=7a9c027159fe9e1bbc2cd38a8a2914bff0d5abd9","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9639817dac8bbbaa64d09efad7464ccc405527c7","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WZZBKUHQFGSKGNXXKICSRPL7AMVW5M5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/","https://security.netapp.com/advisory/ntap-20220707-0008/","https://www.debian.org/security/2022/dsa-5169","https://www.openssl.org/news/secadv/20220621.txt","http://seclists.org/fulldisclosure/2024/Nov/0","https://gitlab.com/fraf0/cve-2022-1292-re_score-analysis"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-2068","description":"In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze)."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.19"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-2068","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-2068","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.19"],"available":[{"date":"2022-06-21","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.19"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-2068","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-2068","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-2068","date":"2026-10-08","epss":0.95404,"percentile":0.99869}],"risk":47.702,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-2068"},"relatedVulnerabilities":[{"id":"CVE-2022-2068","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-2068","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-2068","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-2068","date":"2026-10-08","epss":0.95404,"percentile":0.99869}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2c9c35870601b4a44d86ddbf512b38df38285cfa","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=7a9c027159fe9e1bbc2cd38a8a2914bff0d5abd9","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9639817dac8bbbaa64d09efad7464ccc405527c7","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WZZBKUHQFGSKGNXXKICSRPL7AMVW5M5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/","https://security.netapp.com/advisory/ntap-20220707-0008/","https://www.debian.org/security/2022/dsa-5169","https://www.openssl.org/news/secadv/20220621.txt","http://seclists.org/fulldisclosure/2024/Nov/0","https://gitlab.com/fraf0/cve-2022-1292-re_score-analysis"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-2068","description":"In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze)."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3449","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3449","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.9"],"available":[{"date":"2021-03-25","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3449","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3449","date":"2026-10-08","epss":0.63542,"percentile":0.99195}],"risk":47.6565,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3449"},"relatedVulnerabilities":[{"id":"CVE-2021-3449","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3449","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3449","date":"2026-10-08","epss":0.63542,"percentile":0.99195}],"urls":["http://www.openwall.com/lists/oss-security/2021/03/27/1","http://www.openwall.com/lists/oss-security/2021/03/27/2","http://www.openwall.com/lists/oss-security/2021/03/28/3","http://www.openwall.com/lists/oss-security/2021/03/28/4","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-772220.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=fb9fa6b51defd48157eeb207f52181f735d96148","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44845","https://kc.mcafee.com/corporate/index?page=content&id=SB10356","https://lists.debian.org/debian-lts-announce/2021/08/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP/","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0013","https://security.FreeBSD.org/advisories/FreeBSD-SA-21:07.openssl.asc","https://security.gentoo.org/glsa/202103-03","https://security.netapp.com/advisory/ntap-20210326-0006/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd","https://www.debian.org/security/2021/dsa-4875","https://www.openssl.org/news/secadv/20210325.txt","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-05","https://www.tenable.com/security/tns-2021-06","https://www.tenable.com/security/tns-2021-09","https://www.tenable.com/security/tns-2021-10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3449","description":"An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j)."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-3449","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3449","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.9"],"available":[{"date":"2021-03-25","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3449","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3449","date":"2026-10-08","epss":0.63542,"percentile":0.99195}],"risk":47.6565,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3449"},"relatedVulnerabilities":[{"id":"CVE-2021-3449","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3449","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3449","date":"2026-10-08","epss":0.63542,"percentile":0.99195}],"urls":["http://www.openwall.com/lists/oss-security/2021/03/27/1","http://www.openwall.com/lists/oss-security/2021/03/27/2","http://www.openwall.com/lists/oss-security/2021/03/28/3","http://www.openwall.com/lists/oss-security/2021/03/28/4","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-772220.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=fb9fa6b51defd48157eeb207f52181f735d96148","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44845","https://kc.mcafee.com/corporate/index?page=content&id=SB10356","https://lists.debian.org/debian-lts-announce/2021/08/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP/","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0013","https://security.FreeBSD.org/advisories/FreeBSD-SA-21:07.openssl.asc","https://security.gentoo.org/glsa/202103-03","https://security.netapp.com/advisory/ntap-20210326-0006/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd","https://www.debian.org/security/2021/dsa-4875","https://www.openssl.org/news/secadv/20210325.txt","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-05","https://www.tenable.com/security/tns-2021-06","https://www.tenable.com/security/tns-2021-09","https://www.tenable.com/security/tns-2021-10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3449","description":"An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j)."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.34"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5q99-f34m-67gc","versionConstraint":">=8.5.0,<8.5.34 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5q99-f34m-67gc","fix":{"state":"fixed","versions":["8.5.34"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"8.5.34"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-11784","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11784","date":"2026-10-08","epss":0.9768,"percentile":0.99904}],"risk":45.42119999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-11784","https://access.redhat.com/errata/RHSA-2019:0130","https://access.redhat.com/errata/RHSA-2019:0131","https://access.redhat.com/errata/RHSA-2019:0485","https://access.redhat.com/errata/RHSA-2019:1529","https://kc.mcafee.com/corporate/index?page=content&id=SB10284","https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/23134c9b5a23892a205dc140cdd8c9c0add233600f76b313dda6bd75@%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/5c0e00fd31efc11e147bf99d0f03c00a734447d3b131ab0818644cdb@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/eb6efa8d59c45a7a9eff94c4b925467d3b3fec8ba7697f3daa314b04@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a@%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2018/10/msg00005.html","https://lists.debian.org/debian-lts-announce/2018/10/msg00006.html","https://seclists.org/bugtraq/2019/Dec/43","https://www.debian.org/security/2019/dsa-4596","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00030.html","http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.html","http://packetstormsecurity.com/files/163456/Apache-Tomcat-9.0.0M1-Open-Redirect.html","https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/23134c9b5a23892a205dc140cdd8c9c0add233600f76b313dda6bd75%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/5c0e00fd31efc11e147bf99d0f03c00a734447d3b131ab0818644cdb%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/eb6efa8d59c45a7a9eff94c4b925467d3b3fec8ba7697f3daa314b04%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E","https://web.archive.org/web/20200227030058/http://www.securityfocus.com/bid/105524","https://github.com/apache/tomcat/commit/b76e1dfb3dec3789cc700f8d022c872eb947a221","https://github.com/apache/tomcat/commit/efb860b3ff8ebcf606199b8d0d432f76898040da","https://github.com/apache/tomcat/commit/f9f147359b7c95511b64cd99bbc47917c01b3879","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZ4PX4B3QTKRM35VJAVIEOPZAF76RPBP","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZ4PX4B3QTKRM35VJAVIEOPZAF76RPBP","https://security.netapp.com/advisory/ntap-20181014-0002","https://usn.ubuntu.com/3787-1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5q99-f34m-67gc","description":"Apache Tomcat Open Redirect vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2018-11784","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-11784","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11784","date":"2026-10-08","epss":0.9768,"percentile":0.99904}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00030.html","http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.html","http://packetstormsecurity.com/files/163456/Apache-Tomcat-9.0.0M1-Open-Redirect.html","http://www.securityfocus.com/bid/105524","https://access.redhat.com/errata/RHSA-2019:0130","https://access.redhat.com/errata/RHSA-2019:0131","https://access.redhat.com/errata/RHSA-2019:0485","https://access.redhat.com/errata/RHSA-2019:1529","https://kc.mcafee.com/corporate/index?page=content&id=SB10284","https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/23134c9b5a23892a205dc140cdd8c9c0add233600f76b313dda6bd75%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/5c0e00fd31efc11e147bf99d0f03c00a734447d3b131ab0818644cdb%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/eb6efa8d59c45a7a9eff94c4b925467d3b3fec8ba7697f3daa314b04%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2018/10/msg00005.html","https://lists.debian.org/debian-lts-announce/2018/10/msg00006.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZ4PX4B3QTKRM35VJAVIEOPZAF76RPBP/","https://seclists.org/bugtraq/2019/Dec/43","https://security.netapp.com/advisory/ntap-20181014-0002/","https://usn.ubuntu.com/3787-1/","https://www.debian.org/security/2019/dsa-4596","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-11784","description":"When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.21"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-0286","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-0286","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.21"],"available":[{"date":"2023-02-07","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-0286","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0286","cwe":"CWE-843","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0286","date":"2026-10-08","epss":0.59501,"percentile":0.99104}],"risk":44.625750000000004,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-0286"},"relatedVulnerabilities":[{"id":"CVE-2023-0286","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-0286","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0286","cwe":"CWE-843","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0286","date":"2026-10-08","epss":0.59501,"percentile":0.99104}],"urls":["https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.6.2-relnotes.txt","https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/018_x509.patch.sig","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2c6c9d439b484e1ba9830d8454a34fa4f80fdfe9","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2f7530077e0ef79d98718138716bc51ca0cad658","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fd2af07dc083a350c959147097003a14a5e8ac4d","https://security.gentoo.org/glsa/202402-08","https://www.openssl.org/news/secadv/20230207.txt","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-0286","description":"There is a type confusion vulnerability relating to X.400 address processing\ninside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but\nthe public structure definition for GENERAL_NAME incorrectly specified the type\nof the x400Address field as ASN1_TYPE. This field is subsequently interpreted by\nthe OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an\nASN1_STRING.\n\nWhen CRL checking is enabled (i.e. the application sets the\nX509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass\narbitrary pointers to a memcmp call, enabling them to read memory contents or\nenact a denial of service. In most cases, the attack requires the attacker to\nprovide both the certificate chain and CRL, neither of which need to have a\nvalid signature. If the attacker only controls one of these inputs, the other\ninput must already contain an X.400 address as a CRL distribution point, which\nis uncommon. As such, this vulnerability is most likely to only affect\napplications which have implemented their own functionality for retrieving CRLs\nover a network."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.21"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-0286","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-0286","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.21"],"available":[{"date":"2023-02-07","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-0286","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0286","cwe":"CWE-843","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0286","date":"2026-10-08","epss":0.59501,"percentile":0.99104}],"risk":44.625750000000004,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-0286"},"relatedVulnerabilities":[{"id":"CVE-2023-0286","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-0286","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0286","cwe":"CWE-843","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0286","date":"2026-10-08","epss":0.59501,"percentile":0.99104}],"urls":["https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.6.2-relnotes.txt","https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/018_x509.patch.sig","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2c6c9d439b484e1ba9830d8454a34fa4f80fdfe9","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2f7530077e0ef79d98718138716bc51ca0cad658","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fd2af07dc083a350c959147097003a14a5e8ac4d","https://security.gentoo.org/glsa/202402-08","https://www.openssl.org/news/secadv/20230207.txt","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-0286","description":"There is a type confusion vulnerability relating to X.400 address processing\ninside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but\nthe public structure definition for GENERAL_NAME incorrectly specified the type\nof the x400Address field as ASN1_TYPE. This field is subsequently interpreted by\nthe OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an\nASN1_STRING.\n\nWhen CRL checking is enabled (i.e. the application sets the\nX509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass\narbitrary pointers to a memcmp call, enabling them to read memory contents or\nenact a denial of service. In most cases, the attack requires the attacker to\nprovide both the certificate chain and CRL, neither of which need to have a\nvalid signature. If the attacker only controls one of these inputs, the other\ninput must already contain an X.400 address as a CRL distribution point, which\nis uncommon. As such, this vulnerability is most likely to only affect\napplications which have implemented their own functionality for retrieving CRLs\nover a network."}]},{"artifact":{"id":"685ff832fa5df143","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-2961","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-2961","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-08","epss":0.8833,"percentile":0.99769}],"risk":44.165,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2961"},"relatedVulnerabilities":[{"id":"CVE-2024-2961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.3,"impactScore":4.8,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-08","epss":0.8833,"percentile":0.99769}],"urls":["http://www.openwall.com/lists/oss-security/2024/04/17/9","http://www.openwall.com/lists/oss-security/2024/04/18/4","http://www.openwall.com/lists/oss-security/2024/04/24/2","http://www.openwall.com/lists/oss-security/2024/05/27/1","http://www.openwall.com/lists/oss-security/2024/05/27/2","http://www.openwall.com/lists/oss-security/2024/05/27/3","http://www.openwall.com/lists/oss-security/2024/05/27/4","http://www.openwall.com/lists/oss-security/2024/05/27/5","http://www.openwall.com/lists/oss-security/2024/05/27/6","http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/05/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/","https://security.netapp.com/advisory/ntap-20240531-0002/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004","https://www.ambionics.io/blog/iconv-cve-2024-2961-p1","https://www.ambionics.io/blog/iconv-cve-2024-2961-p2","https://www.ambionics.io/blog/iconv-cve-2024-2961-p3","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2961","description":"The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable."}]},{"artifact":{"id":"71315b6fa75a7166","cpes":["cpe:2.3:a:libc6:libc6:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-2961","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-2961","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-08","epss":0.8833,"percentile":0.99769}],"risk":44.165,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2961"},"relatedVulnerabilities":[{"id":"CVE-2024-2961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.3,"impactScore":4.8,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-08","epss":0.8833,"percentile":0.99769}],"urls":["http://www.openwall.com/lists/oss-security/2024/04/17/9","http://www.openwall.com/lists/oss-security/2024/04/18/4","http://www.openwall.com/lists/oss-security/2024/04/24/2","http://www.openwall.com/lists/oss-security/2024/05/27/1","http://www.openwall.com/lists/oss-security/2024/05/27/2","http://www.openwall.com/lists/oss-security/2024/05/27/3","http://www.openwall.com/lists/oss-security/2024/05/27/4","http://www.openwall.com/lists/oss-security/2024/05/27/5","http://www.openwall.com/lists/oss-security/2024/05/27/6","http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/05/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/","https://security.netapp.com/advisory/ntap-20240531-0002/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004","https://www.ambionics.io/blog/iconv-cve-2024-2961-p1","https://www.ambionics.io/blog/iconv-cve-2024-2961-p2","https://www.ambionics.io/blog/iconv-cve-2024-2961-p3","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2961","description":"The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable."}]},{"artifact":{"id":"62a0389fd254614a","cpes":["cpe:2.3:a:locales:locales:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.27-3ubuntu1?arch=all&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-2961","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-2961","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-08","epss":0.8833,"percentile":0.99769}],"risk":44.165,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2961"},"relatedVulnerabilities":[{"id":"CVE-2024-2961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.3,"impactScore":4.8,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-08","epss":0.8833,"percentile":0.99769}],"urls":["http://www.openwall.com/lists/oss-security/2024/04/17/9","http://www.openwall.com/lists/oss-security/2024/04/18/4","http://www.openwall.com/lists/oss-security/2024/04/24/2","http://www.openwall.com/lists/oss-security/2024/05/27/1","http://www.openwall.com/lists/oss-security/2024/05/27/2","http://www.openwall.com/lists/oss-security/2024/05/27/3","http://www.openwall.com/lists/oss-security/2024/05/27/4","http://www.openwall.com/lists/oss-security/2024/05/27/5","http://www.openwall.com/lists/oss-security/2024/05/27/6","http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/05/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/","https://security.netapp.com/advisory/ntap-20240531-0002/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004","https://www.ambionics.io/blog/iconv-cve-2024-2961-p1","https://www.ambionics.io/blog/iconv-cve-2024-2961-p2","https://www.ambionics.io/blog/iconv-cve-2024-2961-p3","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2961","description":"The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable."}]},{"artifact":{"id":"6c475aa8af85f1cd","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-2961","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-2961","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-08","epss":0.8833,"percentile":0.99769}],"risk":44.165,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2961"},"relatedVulnerabilities":[{"id":"CVE-2024-2961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.3,"impactScore":4.8,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-08","epss":0.8833,"percentile":0.99769}],"urls":["http://www.openwall.com/lists/oss-security/2024/04/17/9","http://www.openwall.com/lists/oss-security/2024/04/18/4","http://www.openwall.com/lists/oss-security/2024/04/24/2","http://www.openwall.com/lists/oss-security/2024/05/27/1","http://www.openwall.com/lists/oss-security/2024/05/27/2","http://www.openwall.com/lists/oss-security/2024/05/27/3","http://www.openwall.com/lists/oss-security/2024/05/27/4","http://www.openwall.com/lists/oss-security/2024/05/27/5","http://www.openwall.com/lists/oss-security/2024/05/27/6","http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/05/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/","https://security.netapp.com/advisory/ntap-20240531-0002/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004","https://www.ambionics.io/blog/iconv-cve-2024-2961-p1","https://www.ambionics.io/blog/iconv-cve-2024-2961-p2","https://www.ambionics.io/blog/iconv-cve-2024-2961-p3","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2961","description":"The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable."}]},{"artifact":{"id":"0c17bed56057f9e7","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.1?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36221","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36221","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36221","cwe":"CWE-191","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36221","date":"2026-10-08","epss":0.84994,"percentile":0.99709}],"risk":42.497,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36221"},"relatedVulnerabilities":[{"id":"CVE-2020-36221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36221","cwe":"CWE-191","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36221","date":"2026-10-08","epss":0.84994,"percentile":0.99709}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9404","https://bugs.openldap.org/show_bug.cgi?id=9424","https://git.openldap.org/openldap/openldap/-/commit/38ac838e4150c626bbfa0082b7e2cf3a2bb4df31","https://git.openldap.org/openldap/openldap/-/commit/58c1748e81c843c5b6e61648d2a4d1d82b47e842","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36221","description":"An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck)."}]},{"artifact":{"id":"0c17bed56057f9e7","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.1?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36228","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36228","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36228","cwe":"CWE-191","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36228","date":"2026-10-08","epss":0.84994,"percentile":0.99709}],"risk":42.497,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36228"},"relatedVulnerabilities":[{"id":"CVE-2020-36228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36228","cwe":"CWE-191","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36228","date":"2026-10-08","epss":0.84994,"percentile":0.99709}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9427","https://git.openldap.org/openldap/openldap/-/commit/91dccd25c347733b365adc74cb07d074512ed5ad","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36228","description":"An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service."}]},{"artifact":{"id":"d1ea226d64532803","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.1?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36221","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36221","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36221","cwe":"CWE-191","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36221","date":"2026-10-08","epss":0.84994,"percentile":0.99709}],"risk":42.497,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36221"},"relatedVulnerabilities":[{"id":"CVE-2020-36221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36221","cwe":"CWE-191","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36221","date":"2026-10-08","epss":0.84994,"percentile":0.99709}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9404","https://bugs.openldap.org/show_bug.cgi?id=9424","https://git.openldap.org/openldap/openldap/-/commit/38ac838e4150c626bbfa0082b7e2cf3a2bb4df31","https://git.openldap.org/openldap/openldap/-/commit/58c1748e81c843c5b6e61648d2a4d1d82b47e842","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36221","description":"An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck)."}]},{"artifact":{"id":"d1ea226d64532803","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.1?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36228","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36228","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36228","cwe":"CWE-191","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36228","date":"2026-10-08","epss":0.84994,"percentile":0.99709}],"risk":42.497,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36228"},"relatedVulnerabilities":[{"id":"CVE-2020-36228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36228","cwe":"CWE-191","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36228","date":"2026-10-08","epss":0.84994,"percentile":0.99709}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9427","https://git.openldap.org/openldap/openldap/-/commit/91dccd25c347733b365adc74cb07d074512ed5ad","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36228","description":"An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service."}]},{"artifact":{"id":"839771142f972cee","cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*"],"name":"libnghttp2-14","purl":"pkg:deb/ubuntu/libnghttp2-14@1.30.0-1ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=nghttp2","type":"deb","version":"1.30.0-1ubuntu1","language":"","licenses":["BSD-2-clause","Expat","GPL-3","GPL-3+","MIT","SIL-OFL-1.1","all-permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnghttp2-14/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libnghttp2-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nghttp2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-28182","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nghttp2","version":"1.30.0-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-28182","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-28182","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-28182","date":"2026-10-08","epss":0.8496,"percentile":0.99708}],"risk":42.480000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-28182"},"relatedVulnerabilities":[{"id":"CVE-2024-28182","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28182","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-28182","date":"2026-10-08","epss":0.8496,"percentile":0.99708}],"urls":["http://www.openwall.com/lists/oss-security/2024/04/03/16","https://github.com/nghttp2/nghttp2/commit/00201ecd8f982da3b67d4f6868af72a1b03b14e0","https://github.com/nghttp2/nghttp2/commit/d71a4668c6bead55805d18810d633fbb98315af9","https://github.com/nghttp2/nghttp2/security/advisories/GHSA-x6x3-gv8h-m57q","https://lists.debian.org/debian-lts-announce/2024/04/msg00026.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AGOME6ZXJG7664IPQNVE3DL67E3YP3HY/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J6ZMXUGB66VAXDW5J6QSTHM5ET25FGSA/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXJO2EASHM2OQQLGVDY5ZSO7UVDVHTDK/","https://lists.debian.org/debian-lts-announce/2024/09/msg00041.html","https://www.kb.cert.org/vuls/id/421644"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28182","description":"nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync.  This causes excessive CPU usage to decode HPACK stream. nghttp2 v1.61.0 mitigates this vulnerability by limiting the number of CONTINUATION frames it accepts per stream. There is no workaround for this vulnerability."}]},{"artifact":{"id":"f86d3c9a089379e7","cpes":["cpe:2.3:a:org.springframework:spring-webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-webmvc:spring-webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-webmvc:spring_webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_webmvc:spring-webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_webmvc:spring_webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_webmvc:5.0.8.RELEASE:*:*:*:*:*:*:*"],"name":"spring-webmvc","purl":"pkg:maven/org.springframework/spring-webmvc@5.0.8.RELEASE","type":"java-archive","version":"5.0.8.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-webmvc-5.0.8.RELEASE.jar","manifestName":"","pomArtifactID":"spring-webmvc","archiveDigests":[{"value":"7e5fe57590ca8e4468e50fe1d92b0b67aa4a327a","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-webmvc-5.0.8.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g5vr-rgqm-vf78","versionConstraint":"<=5.3.40 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-webmvc","version":"5.0.8.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-g5vr-rgqm-vf78","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-38819","cwe":"CWE-22","type":"Secondary","source":"security@vmware.com"}],"epss":[{"cve":"CVE-2024-38819","date":"2026-10-08","epss":0.5604,"percentile":0.99027}],"risk":42.03,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-38819","https://spring.io/security/cve-2024-38819","https://github.com/spring-projects/spring-framework/issues/33689","https://github.com/spring-projects/spring-framework/commit/3bfbe30a7814c9ea1556d40df9bd87ddb3ba372d","https://github.com/spring-projects/spring-framework/commit/fb7890d73975a3d9e0763e0926df2bd0a608e87e","https://security.netapp.com/advisory/ntap-20250110-0010"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g5vr-rgqm-vf78","description":"Spring Framework Path Traversal vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2024-38819","cvss":[{"type":"Secondary","source":"security@vmware.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-38819","cwe":"CWE-22","type":"Secondary","source":"security@vmware.com"}],"epss":[{"cve":"CVE-2024-38819","date":"2026-10-08","epss":0.5604,"percentile":0.99027}],"urls":["https://spring.io/security/cve-2024-38819","https://security.netapp.com/advisory/ntap-20250110-0010/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-38819","description":"Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.17"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-1292","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.17 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-1292","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.17"],"available":[{"date":"2022-05-04","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.17"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-1292","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-1292","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-1292","date":"2026-10-08","epss":0.82612,"percentile":0.99661}],"risk":41.306,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1292"},"relatedVulnerabilities":[{"id":"CVE-2022-1292","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1292","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-1292","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-1292","date":"2026-10-08","epss":0.82612,"percentile":0.99661}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-953464.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=1ad73b4d27bd8c1b369a3cd453681d3a4f1bb9b2","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=548d3f280a6e737673f5b61fce24bb100108dfeb","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e5fd1728ef4c7a5bf7c7a7163ca60370460a6e23","https://lists.debian.org/debian-lts-announce/2022/05/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VX4KWHPMKYJL6ZLW4M5IU7E5UV5ZWJQU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNU5M7BXMML26G3GPYKFGQYPQDRSNKDD/","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0011","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20220602-0009/","https://security.netapp.com/advisory/ntap-20220729-0004/","https://www.debian.org/security/2022/dsa-5139","https://www.openssl.org/news/secadv/20220503.txt","https://www.oracle.com/security-alerts/cpujul2022.html","https://gitlab.com/fraf0/cve-2022-1292-re_score-analysis"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1292","description":"The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd)."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.17"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-1292","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.17 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-1292","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.17"],"available":[{"date":"2022-05-04","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.17"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-1292","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-1292","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-1292","date":"2026-10-08","epss":0.82612,"percentile":0.99661}],"risk":41.306,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1292"},"relatedVulnerabilities":[{"id":"CVE-2022-1292","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1292","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-1292","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-1292","date":"2026-10-08","epss":0.82612,"percentile":0.99661}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-953464.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=1ad73b4d27bd8c1b369a3cd453681d3a4f1bb9b2","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=548d3f280a6e737673f5b61fce24bb100108dfeb","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e5fd1728ef4c7a5bf7c7a7163ca60370460a6e23","https://lists.debian.org/debian-lts-announce/2022/05/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VX4KWHPMKYJL6ZLW4M5IU7E5UV5ZWJQU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNU5M7BXMML26G3GPYKFGQYPQDRSNKDD/","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0011","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20220602-0009/","https://security.netapp.com/advisory/ntap-20220729-0004/","https://www.debian.org/security/2022/dsa-5139","https://www.openssl.org/news/secadv/20220503.txt","https://www.oracle.com/security-alerts/cpujul2022.html","https://gitlab.com/fraf0/cve-2022-1292-re_score-analysis"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1292","description":"The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.16+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-34169","versionConstraint":"< 11.0.16+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-34169","fix":{"state":"fixed","versions":["11.0.16+8-0ubuntu1~18.04"],"available":[{"date":"2022-08-04","kind":"advisory","version":"11.0.16+8-0ubuntu1~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-34169","cwe":"CWE-681","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-34169","cwe":"CWE-681","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-34169","date":"2026-10-08","epss":0.81759,"percentile":0.99639}],"risk":40.8795,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-34169"},"relatedVulnerabilities":[{"id":"CVE-2022-34169","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-34169","cwe":"CWE-681","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-34169","cwe":"CWE-681","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-34169","date":"2026-10-08","epss":0.81759,"percentile":0.99639}],"urls":["http://packetstormsecurity.com/files/168186/Xalan-J-XSLTC-Integer-Truncation.html","http://www.openwall.com/lists/oss-security/2022/07/19/5","http://www.openwall.com/lists/oss-security/2022/07/19/6","http://www.openwall.com/lists/oss-security/2022/07/20/2","http://www.openwall.com/lists/oss-security/2022/07/20/3","http://www.openwall.com/lists/oss-security/2022/10/18/2","http://www.openwall.com/lists/oss-security/2022/11/04/8","http://www.openwall.com/lists/oss-security/2022/11/07/2","https://lists.apache.org/thread/12pxy4phsry6c34x2ol4fft6xlho4kyw","https://lists.apache.org/thread/2qvl7r43wb4t8p9dd9om1bnkssk07sn8","https://lists.debian.org/debian-lts-announce/2022/10/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4YNJSJ64NPCNKFPNBYITNZU5H3L4D6L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5OZNAZJ4YHLOKRRRZSWRT5OJ25E4XLM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JN3EVGR7FD3ZLV5SBTJXUIDCMSK4QUE2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KO3DXNKZ4EU3UZBT6AAR4XRKCD73KLMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3XPOTPPBZIPFBZHQE5E7OW6PDACUMCJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YULPNO3PAWMEQQZV2C54I3H3ZOXFZUTB/","https://security.gentoo.org/glsa/202401-25","https://security.netapp.com/advisory/ntap-20220729-0009/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2022/dsa-5188","https://www.debian.org/security/2022/dsa-5192","https://www.debian.org/security/2022/dsa-5256","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-34169","description":"The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan."}]},{"artifact":{"id":"839771142f972cee","cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*"],"name":"libnghttp2-14","purl":"pkg:deb/ubuntu/libnghttp2-14@1.30.0-1ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=nghttp2","type":"deb","version":"1.30.0-1ubuntu1","language":"","licenses":["BSD-2-clause","Expat","GPL-3","GPL-3+","MIT","SIL-OFL-1.1","all-permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnghttp2-14/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libnghttp2-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nghttp2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9513","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nghttp2","version":"1.30.0-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9513","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9513","cwe":"CWE-400","type":"Secondary","source":"cret@cert.org"},{"cve":"CVE-2019-9513","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9513","date":"2026-10-08","epss":0.81556,"percentile":0.99636}],"risk":40.778,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9513"},"relatedVulnerabilities":[{"id":"CVE-2019-9513","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.8,"impactScore":6.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"cret@cert.org","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9513","cwe":"CWE-400","type":"Secondary","source":"cret@cert.org"},{"cve":"CVE-2019-9513","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9513","date":"2026-10-08","epss":0.81556,"percentile":0.99636}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00003.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00005.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00014.html","https://access.redhat.com/errata/RHSA-2019:2692","https://access.redhat.com/errata/RHSA-2019:2745","https://access.redhat.com/errata/RHSA-2019:2746","https://access.redhat.com/errata/RHSA-2019:2775","https://access.redhat.com/errata/RHSA-2019:2799","https://access.redhat.com/errata/RHSA-2019:2925","https://access.redhat.com/errata/RHSA-2019:2939","https://access.redhat.com/errata/RHSA-2019:2949","https://access.redhat.com/errata/RHSA-2019:2955","https://access.redhat.com/errata/RHSA-2019:2966","https://access.redhat.com/errata/RHSA-2019:3041","https://access.redhat.com/errata/RHSA-2019:3932","https://access.redhat.com/errata/RHSA-2019:3933","https://access.redhat.com/errata/RHSA-2019:3935","https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md","https://kb.cert.org/vuls/id/605641/","https://kc.mcafee.com/corporate/index?page=content&id=SB10296","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JUBYAF6ED3O4XCHQ5C2HYENJLXYXZC4M/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZLUYPYY3RX4ZJDWZRJIKSULYRJ4PXW7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPAEC4FWL4UU4LDEGPY5NPALU24FFQD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TAZZEVTCN2B4WT6AIBJ7XGYJMBTORJU5/","https://seclists.org/bugtraq/2019/Aug/40","https://seclists.org/bugtraq/2019/Sep/1","https://security.netapp.com/advisory/ntap-20190823-0002/","https://security.netapp.com/advisory/ntap-20190823-0005/","https://support.f5.com/csp/article/K02591030","https://support.f5.com/csp/article/K02591030?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4099-1/","https://www.debian.org/security/2019/dsa-4505","https://www.debian.org/security/2019/dsa-4511","https://www.debian.org/security/2020/dsa-4669","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.synology.com/security/advisory/Synology_SA_19_33"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9513","description":"Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.55"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-344f-f5vg-2jfj","versionConstraint":">=8.0.0,<8.5.55 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-344f-f5vg-2jfj","fix":{"state":"fixed","versions":["8.5.55"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"8.5.55"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9484","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-9484","date":"2026-10-08","epss":0.5552,"percentile":0.99016}],"risk":40.251999999999995,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-9484","https://lists.apache.org/thread.html/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf70f53af27e04869bdac18b1fc14a3ee529e59eb12292c8791a77926@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r26950738f4b4ca2d256597cf391d52d3450fa665c297ea5ca38f5469@%3Cusers.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/05/msg00020.html","http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00057.html","https://lists.apache.org/thread.html/r7bc247fffcb1d58415215c861d2354bd653c86266230d78a93c71ae2@%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","http://packetstormsecurity.com/files/157924/Apache-Tomcat-CVE-2020-9484-Proof-Of-Concept.html","http://seclists.org/fulldisclosure/2020/Jun/6","https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed@%3Cdev.tomcat.apache.org%3E","https://security.gentoo.org/glsa/202006-21","https://lists.debian.org/debian-lts-announce/2020/07/msg00010.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.debian.org/security/2020/dsa-4727","https://kc.mcafee.com/corporate/index?page=content&id=SB10332","https://lists.apache.org/thread.html/r123b3ebe389f46f9d337923f393cdae4d3e9b78d982d706712f0898c@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/raa4123e472175bb052fbba165d37187cea923f755e8f3f30d124cb3f@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc8473b08abdf3c16494ed817bec1717a0ee0c8080315bc27db5f21c3@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf59c72572b9fee674a5d5cc6afeca4ffc3918a02c354a81cc50b7119@%3Ccommits.tomee.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cusers.tomcat.apache.org%3E","http://www.openwall.com/lists/oss-security/2021/03/01/2","https://lists.apache.org/thread.html/r8dd19c514face6dd85fd4eab0271854883f40c7307926c1f7cd5400c@%3Ccommits.tomee.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rc1778b38e74b5b6142414d57623bd55b023a72361f422836782fca3c@%3Cdev.tomcat.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/apache/tomcat/commit/3aa8f28db7efb311cdd1b6fe15a9cd3b167a2222.patch","https://github.com/apache/tomcat/commit/bb33048e3f9b4f2b70e4da2e6c4e34ca89023b1b","https://bugzilla.suse.com/show_bug.cgi?id=1171928","https://github.com/apache/tomcat/commit/4785433a226a20df6acbea49296e1ce7e23de453","https://github.com/apache/tomcat/commit/6d66e99ef85da93e4d2c2a536ca51aa3418bfaf4","https://github.com/apache/tomcat/commit/74b105657ffbd1d1de80455f03446c3bbf30d1f5","https://github.com/apache/tomcat/commit/93f0cc403a9210d469afc2bd9cf03ab3251c6f35","https://tomcat.apache.org/security-9.html","https://tomcat.apache.org/security-8.html","https://tomcat.apache.org/security-7.html","https://tomcat.apache.org/security-10.html","https://security.netapp.com/advisory/ntap-20200528-0005","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJ7XHKWJWDNWXUJH6UB7CLIW4TWOZ26N","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GIQHXENTLYUNOES4LXVNJ2NCUQQRF5VJ","https://usn.ubuntu.com/4448-1","https://usn.ubuntu.com/4596-1","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WJ7XHKWJWDNWXUJH6UB7CLIW4TWOZ26N","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GIQHXENTLYUNOES4LXVNJ2NCUQQRF5VJ","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r123b3ebe389f46f9d337923f393cdae4d3e9b78d982d706712f0898c%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r26950738f4b4ca2d256597cf391d52d3450fa665c297ea5ca38f5469%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7bc247fffcb1d58415215c861d2354bd653c86266230d78a93c71ae2%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r8dd19c514face6dd85fd4eab0271854883f40c7307926c1f7cd5400c%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/raa4123e472175bb052fbba165d37187cea923f755e8f3f30d124cb3f%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rc1778b38e74b5b6142414d57623bd55b023a72361f422836782fca3c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rc8473b08abdf3c16494ed817bec1717a0ee0c8080315bc27db5f21c3%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf59c72572b9fee674a5d5cc6afeca4ffc3918a02c354a81cc50b7119%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf70f53af27e04869bdac18b1fc14a3ee529e59eb12292c8791a77926%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.apache.org%3E"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-344f-f5vg-2jfj","description":"Potential remote code execution in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2020-9484","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.4,"impactScore":6.5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9484","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-9484","date":"2026-10-08","epss":0.5552,"percentile":0.99016}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00057.html","http://packetstormsecurity.com/files/157924/Apache-Tomcat-CVE-2020-9484-Proof-Of-Concept.html","http://seclists.org/fulldisclosure/2020/Jun/6","http://www.openwall.com/lists/oss-security/2021/03/01/2","https://kc.mcafee.com/corporate/index?page=content&id=SB10332","https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r123b3ebe389f46f9d337923f393cdae4d3e9b78d982d706712f0898c%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r26950738f4b4ca2d256597cf391d52d3450fa665c297ea5ca38f5469%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7bc247fffcb1d58415215c861d2354bd653c86266230d78a93c71ae2%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r8dd19c514face6dd85fd4eab0271854883f40c7307926c1f7cd5400c%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/raa4123e472175bb052fbba165d37187cea923f755e8f3f30d124cb3f%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rc1778b38e74b5b6142414d57623bd55b023a72361f422836782fca3c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rc8473b08abdf3c16494ed817bec1717a0ee0c8080315bc27db5f21c3%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf59c72572b9fee674a5d5cc6afeca4ffc3918a02c354a81cc50b7119%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf70f53af27e04869bdac18b1fc14a3ee529e59eb12292c8791a77926%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cusers.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/05/msg00020.html","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00010.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GIQHXENTLYUNOES4LXVNJ2NCUQQRF5VJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WJ7XHKWJWDNWXUJH6UB7CLIW4TWOZ26N/","https://security.gentoo.org/glsa/202006-21","https://security.netapp.com/advisory/ntap-20200528-0005/","https://usn.ubuntu.com/4448-1/","https://usn.ubuntu.com/4596-1/","https://www.debian.org/security/2020/dsa-4727","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-9484","description":"When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter=\"null\" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed."}]},{"artifact":{"id":"0c17bed56057f9e7","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.1?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36222","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36222","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36222","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36222","date":"2026-10-08","epss":0.77236,"percentile":0.99545}],"risk":38.618,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36222"},"relatedVulnerabilities":[{"id":"CVE-2020-36222","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36222","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36222","date":"2026-10-08","epss":0.77236,"percentile":0.99545}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9406","https://bugs.openldap.org/show_bug.cgi?id=9407","https://git.openldap.org/openldap/openldap/-/commit/02dfc32d658fadc25e4040f78e36592f6e1e1ca0","https://git.openldap.org/openldap/openldap/-/commit/6ed057b5b728b50746c869bcc9c1f85d0bbbf6ed","https://git.openldap.org/openldap/openldap/-/commit/6ed057b5b728b50746c869bcc9c1f85d0bbbf6ed.aa","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36222","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service."}]},{"artifact":{"id":"0c17bed56057f9e7","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.1?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36227","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36227","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36227","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36227","date":"2026-10-08","epss":0.77236,"percentile":0.99545}],"risk":38.618,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36227"},"relatedVulnerabilities":[{"id":"CVE-2020-36227","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36227","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36227","date":"2026-10-08","epss":0.77236,"percentile":0.99545}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9428","https://git.openldap.org/openldap/openldap/-/commit/9d0e8485f3113505743baabf1167e01e4558ccf5","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36227","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service."}]},{"artifact":{"id":"d1ea226d64532803","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.1?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36222","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36222","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36222","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36222","date":"2026-10-08","epss":0.77236,"percentile":0.99545}],"risk":38.618,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36222"},"relatedVulnerabilities":[{"id":"CVE-2020-36222","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36222","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36222","date":"2026-10-08","epss":0.77236,"percentile":0.99545}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9406","https://bugs.openldap.org/show_bug.cgi?id=9407","https://git.openldap.org/openldap/openldap/-/commit/02dfc32d658fadc25e4040f78e36592f6e1e1ca0","https://git.openldap.org/openldap/openldap/-/commit/6ed057b5b728b50746c869bcc9c1f85d0bbbf6ed","https://git.openldap.org/openldap/openldap/-/commit/6ed057b5b728b50746c869bcc9c1f85d0bbbf6ed.aa","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36222","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service."}]},{"artifact":{"id":"d1ea226d64532803","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.1?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36227","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36227","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36227","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36227","date":"2026-10-08","epss":0.77236,"percentile":0.99545}],"risk":38.618,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36227"},"relatedVulnerabilities":[{"id":"CVE-2020-36227","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36227","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36227","date":"2026-10-08","epss":0.77236,"percentile":0.99545}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9428","https://git.openldap.org/openldap/openldap/-/commit/9d0e8485f3113505743baabf1167e01e4558ccf5","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36227","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.23"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-2650","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.23 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-2650","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.23"],"available":[{"date":"2023-05-30","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.23"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2650","date":"2026-10-08","epss":0.75116,"percentile":0.995}],"risk":37.558,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-2650"},"relatedVulnerabilities":[{"id":"CVE-2023-2650","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2650","date":"2026-10-08","epss":0.75116,"percentile":0.995}],"urls":["http://www.openwall.com/lists/oss-security/2023/05/30/1","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=423a2bc737a908ad0c77bda470b2b59dc879936b","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=853c5e56ee0b8650c73140816bb8b91d6163422c","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9e209944b35cf82368071f160a744b6178f9b098","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db779b0e10b047f2585615e0b8f2acdf21f8544a","https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0009","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230703-0001/","https://security.netapp.com/advisory/ntap-20231027-0009/","https://www.debian.org/security/2023/dsa-5417","https://www.openssl.org/news/secadv/20230530.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2650","description":"Issue summary: Processing some specially crafted ASN.1 object identifiers or\ndata containing them may be very slow.\n\nImpact summary: Applications that use OBJ_obj2txt() directly, or use any of\nthe OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message\nsize limit may experience notable to very long delays when processing those\nmessages, which may lead to a Denial of Service.\n\nAn OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers -\nmost of which have no size limit.  OBJ_obj2txt() may be used to translate\nan ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL\ntype ASN1_OBJECT) to its canonical numeric text form, which are the\nsub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by\nperiods.\n\nWhen one of the sub-identifiers in the OBJECT IDENTIFIER is very large\n(these are sizes that are seen as absurdly large, taking up tens or hundreds\nof KiBs), the translation to a decimal number in text may take a very long\ntime.  The time complexity is O(n^2) with 'n' being the size of the\nsub-identifiers in bytes (*).\n\nWith OpenSSL 3.0, support to fetch cryptographic algorithms using names /\nidentifiers in string form was introduced.  This includes using OBJECT\nIDENTIFIERs in canonical numeric text form as identifiers for fetching\nalgorithms.\n\nSuch OBJECT IDENTIFIERs may be received through the ASN.1 structure\nAlgorithmIdentifier, which is commonly used in multiple protocols to specify\nwhat cryptographic algorithm should be used to sign or verify, encrypt or\ndecrypt, or digest passed data.\n\nApplications that call OBJ_obj2txt() directly with untrusted data are\naffected, with any version of OpenSSL.  If the use is for the mere purpose\nof display, the severity is considered low.\n\nIn OpenSSL 3.0 and newer, this affects the subsystems OCSP, PKCS7/SMIME,\nCMS, CMP/CRMF or TS.  It also impacts anything that processes X.509\ncertificates, including simple things like verifying its signature.\n\nThe impact on TLS is relatively low, because all versions of OpenSSL have a\n100KiB limit on the peer's certificate chain.  Additionally, this only\nimpacts clients, or servers that have explicitly enabled client\nauthentication.\n\nIn OpenSSL 1.1.1 and 1.0.2, this only affects displaying diverse objects,\nsuch as X.509 certificates.  This is assumed to not happen in such a way\nthat it would cause a Denial of Service, so these versions are considered\nnot affected by this issue in such a way that it would be cause for concern,\nand the severity is therefore considered low."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.23"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-2650","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.23 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-2650","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.23"],"available":[{"date":"2023-05-30","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.23"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2650","date":"2026-10-08","epss":0.75116,"percentile":0.995}],"risk":37.558,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-2650"},"relatedVulnerabilities":[{"id":"CVE-2023-2650","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2650","date":"2026-10-08","epss":0.75116,"percentile":0.995}],"urls":["http://www.openwall.com/lists/oss-security/2023/05/30/1","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=423a2bc737a908ad0c77bda470b2b59dc879936b","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=853c5e56ee0b8650c73140816bb8b91d6163422c","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9e209944b35cf82368071f160a744b6178f9b098","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db779b0e10b047f2585615e0b8f2acdf21f8544a","https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0009","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230703-0001/","https://security.netapp.com/advisory/ntap-20231027-0009/","https://www.debian.org/security/2023/dsa-5417","https://www.openssl.org/news/secadv/20230530.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2650","description":"Issue summary: Processing some specially crafted ASN.1 object identifiers or\ndata containing them may be very slow.\n\nImpact summary: Applications that use OBJ_obj2txt() directly, or use any of\nthe OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message\nsize limit may experience notable to very long delays when processing those\nmessages, which may lead to a Denial of Service.\n\nAn OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers -\nmost of which have no size limit.  OBJ_obj2txt() may be used to translate\nan ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL\ntype ASN1_OBJECT) to its canonical numeric text form, which are the\nsub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by\nperiods.\n\nWhen one of the sub-identifiers in the OBJECT IDENTIFIER is very large\n(these are sizes that are seen as absurdly large, taking up tens or hundreds\nof KiBs), the translation to a decimal number in text may take a very long\ntime.  The time complexity is O(n^2) with 'n' being the size of the\nsub-identifiers in bytes (*).\n\nWith OpenSSL 3.0, support to fetch cryptographic algorithms using names /\nidentifiers in string form was introduced.  This includes using OBJECT\nIDENTIFIERs in canonical numeric text form as identifiers for fetching\nalgorithms.\n\nSuch OBJECT IDENTIFIERs may be received through the ASN.1 structure\nAlgorithmIdentifier, which is commonly used in multiple protocols to specify\nwhat cryptographic algorithm should be used to sign or verify, encrypt or\ndecrypt, or digest passed data.\n\nApplications that call OBJ_obj2txt() directly with untrusted data are\naffected, with any version of OpenSSL.  If the use is for the mere purpose\nof display, the severity is considered low.\n\nIn OpenSSL 3.0 and newer, this affects the subsystems OCSP, PKCS7/SMIME,\nCMS, CMP/CRMF or TS.  It also impacts anything that processes X.509\ncertificates, including simple things like verifying its signature.\n\nThe impact on TLS is relatively low, because all versions of OpenSSL have a\n100KiB limit on the peer's certificate chain.  Additionally, this only\nimpacts clients, or servers that have explicitly enabled client\nauthentication.\n\nIn OpenSSL 1.1.1 and 1.0.2, this only affects displaying diverse objects,\nsuch as X.509 certificates.  This is assumed to not happen in such a way\nthat it would cause a Denial of Service, so these versions are considered\nnot affected by this issue in such a way that it would be cause for concern,\nand the severity is therefore considered low."}]},{"artifact":{"id":"0b1c74783f88c915","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6965","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2025-6965","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-6965","cwe":"CWE-197","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-6965","date":"2026-10-08","epss":0.71394,"percentile":0.99401}],"risk":35.697,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-6965"},"relatedVulnerabilities":[{"id":"CVE-2025-6965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.3,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:L/U:Green","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6965","cwe":"CWE-197","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-6965","date":"2026-10-08","epss":0.71394,"percentile":0.99401}],"urls":["https://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8","http://seclists.org/fulldisclosure/2025/Sep/49","http://seclists.org/fulldisclosure/2025/Sep/53","http://seclists.org/fulldisclosure/2025/Sep/56","http://seclists.org/fulldisclosure/2025/Sep/57","http://seclists.org/fulldisclosure/2025/Sep/58","http://www.openwall.com/lists/oss-security/2025/09/06/1","https://cert-portal.siemens.com/productcert/html/ssa-225816.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6965","description":"There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3p2h-wqq4-wf4h","versionConstraint":">=8.5.0,<=8.5.100 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-3p2h-wqq4-wf4h","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-31650","cwe":"CWE-459","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2025-31650","cwe":"CWE-459","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-31650","date":"2026-10-08","epss":0.61322,"percentile":0.99144}],"risk":35.566759999999995,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-31650","https://lists.apache.org/thread/j6zzk0y3yym9pzfzkq5vcyxzz0yzh826","http://www.openwall.com/lists/oss-security/2025/04/28/2","https://github.com/apache/tomcat/commit/1eef1dc459c45f1e421d8bd25ef340fc1cc34edc","https://github.com/apache/tomcat/commit/40ae788c2e64d018b4e58cd4210bb96434d0100d","https://github.com/apache/tomcat/commit/75554da2fc5574862510ae6f0d7b3d78937f1d40","https://github.com/apache/tomcat/commit/8cc3b8fb3f2d8d4d6a757e014f19d1fafa948a60","https://github.com/apache/tomcat/commit/b7674782679e1514a0d154166b1d04d38aaac4a9","https://github.com/apache/tomcat/commit/b98e74f517b36929f4208506e5adad22cb767baa","https://github.com/apache/tomcat/commit/cba1a0fe1289ee7f5dd46c61c38d1e1ac5437bff","https://github.com/apache/tomcat/commit/ded0285b96b4d3f5560dfc8856ad5ec4a9b50ba9","https://github.com/apache/tomcat/commit/f619e6a05029538886d5a9d987925d573b5bb8c2","https://tomcat.apache.org/security-10.html","https://tomcat.apache.org/security-11.html","https://tomcat.apache.org/security-9.html","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3p2h-wqq4-wf4h","description":"Apache Tomcat Denial of Service via invalid HTTP priority header"},"relatedVulnerabilities":[{"id":"CVE-2025-31650","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-31650","cwe":"CWE-459","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2025-31650","cwe":"CWE-459","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-31650","date":"2026-10-08","epss":0.61322,"percentile":0.99144}],"urls":["https://lists.apache.org/thread/j6zzk0y3yym9pzfzkq5vcyxzz0yzh826","http://www.openwall.com/lists/oss-security/2025/04/28/2","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-31650","description":"Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service.\n\nThis issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.90 though 8.5.100.\n\n\nUsers are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.40"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjpq-gp5q-8q6w","versionConstraint":">=8.5.0,<8.5.40 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-jjpq-gp5q-8q6w","fix":{"state":"fixed","versions":["8.5.40"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"8.5.40"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0221","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0221","date":"2026-10-08","epss":0.59194,"percentile":0.99097}],"risk":32.852669999999996,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0221","https://lists.apache.org/thread.html/6e6e9eacf7b28fd63d249711e9d3ccd4e0a83f556e324aee37be5a8c@%3Cannounce.tomcat.apache.org%3E","https://access.redhat.com/errata/RHSA-2019:3929","https://access.redhat.com/errata/RHSA-2019:3931","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a@%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/05/msg00044.html","https://lists.debian.org/debian-lts-announce/2019/08/msg00015.html","https://seclists.org/bugtraq/2019/Dec/43","https://security.gentoo.org/glsa/202003-43","https://support.f5.com/csp/article/K13184144?utm_source=f5support&amp;utm_medium=RSS","https://www.debian.org/security/2019/dsa-4596","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00090.html","http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00054.html","http://seclists.org/fulldisclosure/2019/May/50","http://packetstormsecurity.com/files/163457/Apache-Tomcat-9.0.0.M1-Cross-Site-Scripting.html","https://lists.apache.org/thread.html/6e6e9eacf7b28fd63d249711e9d3ccd4e0a83f556e324aee37be5a8c%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E","https://support.f5.com/csp/article/K13184144?utm_source=f5support&amp%3Butm_medium=RSS","https://web.archive.org/web/20200227055048/http://www.securityfocus.com/bid/108545","https://github.com/apache/tomcat/commit/15fcd166ea2c1bb79e8541b8e1a43da9c452ceea","https://github.com/apache/tomcat/commit/44ec74c44dcd05cd7e90967c04d40b51440ecd7e","https://github.com/apache/tomcat/commit/4fcdf706f3ecf35912a600242f89637f5acb32da","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NPHQEL5AQ6LZSZD2Y6TYZ4RC3WI7NXJ3","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZQTZ5BJ5F4KV6N53SGNKSW3UY5DBIQ46","https://security.netapp.com/advisory/ntap-20190606-0001","https://tomcat.apache.org/security-7.html","https://tomcat.apache.org/security-8.html","https://tomcat.apache.org/security-9.html","https://usn.ubuntu.com/4128-1","https://usn.ubuntu.com/4128-2","https://wwws.nightwatchcybersecurity.com/2019/05/27/xss-in-ssi-printenv-command-apache-tomcat-cve-2019-0221","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NPHQEL5AQ6LZSZD2Y6TYZ4RC3WI7NXJ3","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQTZ5BJ5F4KV6N53SGNKSW3UY5DBIQ46"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjpq-gp5q-8q6w","description":"Cross-site scripting in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2019-0221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0221","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0221","date":"2026-10-08","epss":0.59194,"percentile":0.99097}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00090.html","http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00054.html","http://packetstormsecurity.com/files/163457/Apache-Tomcat-9.0.0.M1-Cross-Site-Scripting.html","http://seclists.org/fulldisclosure/2019/May/50","http://www.securityfocus.com/bid/108545","https://access.redhat.com/errata/RHSA-2019:3929","https://access.redhat.com/errata/RHSA-2019:3931","https://lists.apache.org/thread.html/6e6e9eacf7b28fd63d249711e9d3ccd4e0a83f556e324aee37be5a8c%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/05/msg00044.html","https://lists.debian.org/debian-lts-announce/2019/08/msg00015.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NPHQEL5AQ6LZSZD2Y6TYZ4RC3WI7NXJ3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQTZ5BJ5F4KV6N53SGNKSW3UY5DBIQ46/","https://seclists.org/bugtraq/2019/Dec/43","https://security.gentoo.org/glsa/202003-43","https://security.netapp.com/advisory/ntap-20190606-0001/","https://support.f5.com/csp/article/K13184144?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4128-1/","https://usn.ubuntu.com/4128-2/","https://www.debian.org/security/2019/dsa-4596","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://wwws.nightwatchcybersecurity.com/2019/05/27/xss-in-ssi-printenv-command-apache-tomcat-cve-2019-0221/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0221","description":"The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website."}]},{"artifact":{"id":"0c17bed56057f9e7","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.1?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-29155","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-29155","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.11"],"available":[{"date":"2022-05-17","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-29155","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-29155","date":"2026-10-08","epss":0.64487,"percentile":0.99221}],"risk":32.243500000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-29155"},"relatedVulnerabilities":[{"id":"CVE-2022-29155","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-29155","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-29155","date":"2026-10-08","epss":0.64487,"percentile":0.99221}],"urls":["https://bugs.openldap.org/show_bug.cgi?id=9815","https://lists.debian.org/debian-lts-announce/2022/05/msg00032.html","https://security.netapp.com/advisory/ntap-20220609-0007/","https://www.debian.org/security/2022/dsa-5140"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-29155","description":"In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping."}]},{"artifact":{"id":"d1ea226d64532803","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.1?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-29155","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-29155","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.11"],"available":[{"date":"2022-05-17","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-29155","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-29155","date":"2026-10-08","epss":0.64487,"percentile":0.99221}],"risk":32.243500000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-29155"},"relatedVulnerabilities":[{"id":"CVE-2022-29155","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-29155","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-29155","date":"2026-10-08","epss":0.64487,"percentile":0.99221}],"urls":["https://bugs.openldap.org/show_bug.cgi?id=9815","https://lists.debian.org/debian-lts-announce/2022/05/msg00032.html","https://security.netapp.com/advisory/ntap-20220609-0007/","https://www.debian.org/security/2022/dsa-5140"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-29155","description":"In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping."}]},{"artifact":{"id":"049449a3ce418599","cpes":["cpe:2.3:a:libcups2:libcups2:2.2.7-1ubuntu2.3:*:*:*:*:*:*:*"],"name":"libcups2","purl":"pkg:deb/ubuntu/libcups2@2.2.7-1ubuntu2.3?arch=amd64&distro=ubuntu-18.04&upstream=cups","type":"deb","version":"2.2.7-1ubuntu2.3","language":"","licenses":["BSD-2-clause","GPL-2","GPL-2.0","LGPL-2","LGPL-2.0","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libcups2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libcups2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-47175","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"cups","version":"2.2.7-1ubuntu2.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-47175","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-47175","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-47175","date":"2026-10-08","epss":0.63607,"percentile":0.99198}],"risk":31.8035,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-47175"},"relatedVulnerabilities":[{"id":"CVE-2024-47175","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-47175","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-47175","date":"2026-10-08","epss":0.63607,"percentile":0.99198}],"urls":["https://github.com/OpenPrinting/cups-browsed/security/advisories/GHSA-rj88-6mr5-rcw8","https://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-p9rh-jxmq-gq47","https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-w63j-6g73-wmg5","https://github.com/OpenPrinting/libppd/security/advisories/GHSA-7xfx-47qg-grp6","https://www.cups.org","https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I","http://www.openwall.com/lists/oss-security/2024/09/27/3","https://github.com/OpenPrinting/libppd/commit/d681747ebf12602cb426725eb8ce2753211e2477","https://lists.debian.org/debian-lts-announce/2024/09/msg00047.html","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0016","https://security.netapp.com/advisory/ntap-20241011-0001/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-47175","description":"CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFromIPP2` does not sanitize IPP attributes when creating the PPD buffer. When used in combination with other functions such as `cfGetPrinterAttributes5`, can result in user controlled input and ultimately code execution via Foomatic. This vulnerability can be part of an exploit chain leading to remote code execution (RCE), as described in CVE-2024-47176."}]},{"artifact":{"id":"0c17bed56057f9e7","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.1?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-27212","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-27212","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.10"],"available":[{"date":"2021-02-22","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.10"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-27212","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-27212","date":"2026-10-08","epss":0.63321,"percentile":0.9919}],"risk":31.660500000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-27212"},"relatedVulnerabilities":[{"id":"CVE-2021-27212","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-27212","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-27212","date":"2026-10-08","epss":0.63321,"percentile":0.9919}],"urls":["https://bugs.openldap.org/show_bug.cgi?id=9454","https://git.openldap.org/openldap/openldap/-/commit/3539fc33212b528c56b716584f2c2994af7c30b0","https://git.openldap.org/openldap/openldap/-/commit/9badb73425a67768c09bcaed1a9c26c684af6c30","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00035.html","https://security.netapp.com/advisory/ntap-20210319-0005/","https://www.debian.org/security/2021/dsa-4860"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-27212","description":"In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime."}]},{"artifact":{"id":"d1ea226d64532803","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.1?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-27212","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-27212","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.10"],"available":[{"date":"2021-02-22","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.10"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-27212","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-27212","date":"2026-10-08","epss":0.63321,"percentile":0.9919}],"risk":31.660500000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-27212"},"relatedVulnerabilities":[{"id":"CVE-2021-27212","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-27212","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-27212","date":"2026-10-08","epss":0.63321,"percentile":0.9919}],"urls":["https://bugs.openldap.org/show_bug.cgi?id=9454","https://git.openldap.org/openldap/openldap/-/commit/3539fc33212b528c56b716584f2c2994af7c30b0","https://git.openldap.org/openldap/openldap/-/commit/9badb73425a67768c09bcaed1a9c26c684af6c30","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00035.html","https://security.netapp.com/advisory/ntap-20210319-0005/","https://www.debian.org/security/2021/dsa-4860"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-27212","description":"In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime."}]},{"artifact":{"id":"81f8e17aa26e6e42","cpes":["cpe:2.3:a:org.springframework:spring-web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-web:spring-web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-web:spring_web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_web:spring-web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_web:spring_web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_web:5.0.8.RELEASE:*:*:*:*:*:*:*"],"name":"spring-web","purl":"pkg:maven/org.springframework/spring-web@5.0.8.RELEASE","type":"java-archive","version":"5.0.8.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-web-5.0.8.RELEASE.jar","manifestName":"","pomArtifactID":"spring-web","archiveDigests":[{"value":"fa43cdadb4ab2491fd1d0ddb06c0808e4b60fc85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-web-5.0.8.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"6.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4wrc-f8pq-fpqp","versionConstraint":"<6.0.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-web","version":"5.0.8.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4wrc-f8pq-fpqp","fix":{"state":"fixed","versions":["6.0.0"],"available":[{"date":"2022-12-10","kind":"first-observed","version":"6.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-1000027","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-1000027","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-1000027","date":"2026-10-08","epss":0.33179,"percentile":0.98331}],"risk":31.18826,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2016-1000027","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000027","https://security-tracker.debian.org/tracker/CVE-2016-1000027","https://www.tenable.com/security/research/tra-2016-20","https://github.com/spring-projects/spring-framework/issues/24434","https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-1231625331","https://github.com/spring-projects/spring-framework/commit/5cbe90b2cd91b866a5a9586e460f311860e11cfa","https://support.contrastsecurity.com/hc/en-us/articles/4402400830612-Spring-web-Java-Deserialization-CVE-2016-1000027","https://github.com/spring-projects/spring-framework/issues/21680","https://github.com/spring-projects/spring-framework/commit/2b051b8b321768a4cfef83077db65c6328ffd60f","https://jira.spring.io/browse/SPR-17143?redirect=false","https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-579669626","https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-582313417","https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-744519525","https://security.netapp.com/advisory/ntap-20230420-0009/","https://spring.io/blog/2022/05/11/spring-framework-5-3-20-and-5-2-22-available-now"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4wrc-f8pq-fpqp","description":"Pivotal Spring Framework contains unsafe Java deserialization methods"},"relatedVulnerabilities":[{"id":"CVE-2016-1000027","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-1000027","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-1000027","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-1000027","date":"2026-10-08","epss":0.33179,"percentile":0.98331}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000027","https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-579669626","https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-582313417","https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-744519525","https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2016/1000xxx/CVE-2016-1000027.json","https://security-tracker.debian.org/tracker/CVE-2016-1000027","https://security.netapp.com/advisory/ntap-20230420-0009/","https://spring.io/blog/2022/05/11/spring-framework-5-3-20-and-5-2-22-available-now","https://www.tenable.com/security/research/tra-2016-20"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-1000027","description":"Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data."}]},{"artifact":{"id":"839771142f972cee","cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*"],"name":"libnghttp2-14","purl":"pkg:deb/ubuntu/libnghttp2-14@1.30.0-1ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=nghttp2","type":"deb","version":"1.30.0-1ubuntu1","language":"","licenses":["BSD-2-clause","Expat","GPL-3","GPL-3+","MIT","SIL-OFL-1.1","all-permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnghttp2-14/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libnghttp2-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nghttp2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9511","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nghttp2","version":"1.30.0-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9511","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9511","cwe":"CWE-400","type":"Secondary","source":"cret@cert.org"},{"cve":"CVE-2019-9511","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9511","date":"2026-10-08","epss":0.59547,"percentile":0.99105}],"risk":29.773500000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9511"},"relatedVulnerabilities":[{"id":"CVE-2019-9511","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.8,"impactScore":6.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"cret@cert.org","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9511","cwe":"CWE-400","type":"Secondary","source":"cret@cert.org"},{"cve":"CVE-2019-9511","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9511","date":"2026-10-08","epss":0.59547,"percentile":0.99105}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00003.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00005.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00014.html","https://access.redhat.com/errata/RHSA-2019:2692","https://access.redhat.com/errata/RHSA-2019:2745","https://access.redhat.com/errata/RHSA-2019:2746","https://access.redhat.com/errata/RHSA-2019:2775","https://access.redhat.com/errata/RHSA-2019:2799","https://access.redhat.com/errata/RHSA-2019:2925","https://access.redhat.com/errata/RHSA-2019:2939","https://access.redhat.com/errata/RHSA-2019:2949","https://access.redhat.com/errata/RHSA-2019:2955","https://access.redhat.com/errata/RHSA-2019:2966","https://access.redhat.com/errata/RHSA-2019:3041","https://access.redhat.com/errata/RHSA-2019:3932","https://access.redhat.com/errata/RHSA-2019:3933","https://access.redhat.com/errata/RHSA-2019:3935","https://access.redhat.com/errata/RHSA-2019:4018","https://access.redhat.com/errata/RHSA-2019:4019","https://access.redhat.com/errata/RHSA-2019:4020","https://access.redhat.com/errata/RHSA-2019:4021","https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md","https://kb.cert.org/vuls/id/605641/","https://kc.mcafee.com/corporate/index?page=content&id=SB10296","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BP556LEG3WENHZI5TAQ6ZEBFTJB4E2IS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JUBYAF6ED3O4XCHQ5C2HYENJLXYXZC4M/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZLUYPYY3RX4ZJDWZRJIKSULYRJ4PXW7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPAEC4FWL4UU4LDEGPY5NPALU24FFQD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TAZZEVTCN2B4WT6AIBJ7XGYJMBTORJU5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XHTKU7YQ5EEP2XNSAV4M4VJ7QCBOJMOD/","https://seclists.org/bugtraq/2019/Aug/40","https://seclists.org/bugtraq/2019/Sep/1","https://security.netapp.com/advisory/ntap-20190823-0002/","https://security.netapp.com/advisory/ntap-20190823-0005/","https://support.f5.com/csp/article/K02591030","https://support.f5.com/csp/article/K02591030?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4099-1/","https://www.debian.org/security/2019/dsa-4505","https://www.debian.org/security/2019/dsa-4511","https://www.debian.org/security/2020/dsa-4669","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.synology.com/security/advisory/Synology_SA_19_33"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9511","description":"Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both."}]},{"artifact":{"id":"e5cacd3d2ad9d076","cpes":["cpe:2.3:a:libgnutls30:libgnutls30:3.5.18-1ubuntu1:*:*:*:*:*:*:*"],"name":"libgnutls30","purl":"pkg:deb/ubuntu/libgnutls30@3.5.18-1ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=gnutls28","type":"deb","version":"3.5.18-1ubuntu1","language":"","licenses":["sha256:d3c67562f8ada637da00685c1142be4345ca259373fe01092239fb678d1a7afd"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libgnutls30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libgnutls30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.18-1ubuntu1.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-3829","versionConstraint":"< 3.5.18-1ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"gnutls28","version":"3.5.18-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-3829","fix":{"state":"fixed","versions":["3.5.18-1ubuntu1.1"],"available":[{"date":"2019-05-30","kind":"advisory","version":"3.5.18-1ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-3829","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-3829","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-3829","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-3829","date":"2026-10-08","epss":0.58969,"percentile":0.99092}],"risk":29.484500000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-3829"},"relatedVulnerabilities":[{"id":"CVE-2019-3829","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-3829","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-3829","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-3829","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-3829","date":"2026-10-08","epss":0.58969,"percentile":0.99092}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.html","https://access.redhat.com/errata/RHSA-2019:3600","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3829","https://gitlab.com/gnutls/gnutls/issues/694","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A3ETBUFBB4G7AITAOUYPGXVMBGVXKUAN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7TJIBRJWGWSH6XIO2MXIQ3W6ES4R6I4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WRSOL66LHP4SD3Y2ECJDOGT4K663ECDU/","https://security.gentoo.org/glsa/201904-14","https://security.netapp.com/advisory/ntap-20190619-0004/","https://usn.ubuntu.com/3999-1/","https://www.gnutls.org/security-new.html#GNUTLS-SA-2019-03-27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-3829","description":"A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected."}]},{"artifact":{"id":"c1103d6297198441","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.11.dfsg-0ubuntu2:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.2.11.dfsg-0ubuntu2?arch=amd64&distro=ubuntu-18.04&upstream=zlib","type":"deb","version":"1:1.2.11.dfsg-0ubuntu2","language":"","licenses":["sha256:176de9c848d59ea736369969db73dcbe025da6360dfba52ad034b52d9616b7c3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"fix":{"suggestedVersion":"1:1.2.11.dfsg-0ubuntu2.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-25032","versionConstraint":"< 1:1.2.11.dfsg-0ubuntu2.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"zlib","version":"1:1.2.11.dfsg-0ubuntu2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-25032","fix":{"state":"fixed","versions":["1:1.2.11.dfsg-0ubuntu2.1"],"available":[{"date":"2022-03-30","kind":"advisory","version":"1:1.2.11.dfsg-0ubuntu2.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-25032","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-25032","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-25032","date":"2026-10-08","epss":0.51733,"percentile":0.98922}],"risk":25.8665,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-25032"},"relatedVulnerabilities":[{"id":"CVE-2018-25032","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-25032","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-25032","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-25032","date":"2026-10-08","epss":0.51733,"percentile":0.98922}],"urls":["http://seclists.org/fulldisclosure/2022/May/33","http://seclists.org/fulldisclosure/2022/May/35","http://seclists.org/fulldisclosure/2022/May/38","http://www.openwall.com/lists/oss-security/2022/03/25/2","http://www.openwall.com/lists/oss-security/2022/03/26/1","https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf","https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531","https://github.com/madler/zlib/compare/v1.2.11...v1.2.12","https://github.com/madler/zlib/issues/605","https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html","https://lists.debian.org/debian-lts-announce/2022/05/msg00008.html","https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/","https://security.gentoo.org/glsa/202210-42","https://security.netapp.com/advisory/ntap-20220526-0009/","https://security.netapp.com/advisory/ntap-20220729-0004/","https://support.apple.com/kb/HT213255","https://support.apple.com/kb/HT213256","https://support.apple.com/kb/HT213257","https://www.debian.org/security/2022/dsa-5111","https://www.openwall.com/lists/oss-security/2022/03/24/1","https://www.openwall.com/lists/oss-security/2022/03/28/1","https://www.openwall.com/lists/oss-security/2022/03/28/3","https://www.oracle.com/security-alerts/cpujul2022.html","https://cert-portal.siemens.com/productcert/html/ssa-333517.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-419740.html","https://cert-portal.siemens.com/productcert/html/ssa-470355.html","https://cert-portal.siemens.com/productcert/html/ssa-565386.html","https://cert-portal.siemens.com/productcert/html/ssa-942865.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-25032","description":"zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches."}]},{"artifact":{"id":"88bdd6da7cccc159","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-25236","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-25236","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-25236","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25236","cwe":"CWE-668","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25236","date":"2026-10-08","epss":0.34174,"percentile":0.9837}],"risk":25.6305,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-25236"},"relatedVulnerabilities":[{"id":"CVE-2022-25236","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25236","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25236","cwe":"CWE-668","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25236","date":"2026-10-08","epss":0.34174,"percentile":0.9837}],"urls":["http://packetstormsecurity.com/files/167238/Zoom-XMPP-Stanza-Smuggling-Remote-Code-Execution.html","http://www.openwall.com/lists/oss-security/2022/02/19/1","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/561","https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/","https://security.gentoo.org/glsa/202209-24","https://security.netapp.com/advisory/ntap-20220303-0008/","https://www.debian.org/security/2022/dsa-5085","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25236","description":"xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5j33-cvvr-w245","versionConstraint":">=8.5.0,<=8.5.100 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5j33-cvvr-w245","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-50379","cwe":"CWE-367","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-50379","date":"2026-10-08","epss":0.31824,"percentile":0.98263}],"risk":25.459200000000003,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-50379","https://lists.apache.org/thread/y6lj6q1xnp822g6ro70tn19sgtjmr80r","https://github.com/apache/tomcat/commit/05ddeeaa54df1e2dc427d0164bedd6b79f78d81f","https://github.com/apache/tomcat/commit/43b507ebac9d268b1ea3d908e296cc6e46795c00","https://github.com/apache/tomcat/commit/631500b0c9b2a2a2abb707e3de2e10a5936e5d41","https://github.com/apache/tomcat/commit/684247ae85fa633b9197b32391de59fc54703842","https://github.com/apache/tomcat/commit/8554f6b1722b33a2ce8b0a3fad37825f3a75f2d2","https://github.com/apache/tomcat/commit/cc7a98b57c6dc1df21979fcff94a36e068f4456c","https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.34","https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.2","https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.98","http://www.openwall.com/lists/oss-security/2024/12/17/4","http://www.openwall.com/lists/oss-security/2024/12/18/2","https://security.netapp.com/advisory/ntap-20250103-0003","https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5j33-cvvr-w245","description":"Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2024-50379","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-50379","cwe":"CWE-367","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-50379","date":"2026-10-08","epss":0.31824,"percentile":0.98263}],"urls":["https://lists.apache.org/thread/y6lj6q1xnp822g6ro70tn19sgtjmr80r","http://www.openwall.com/lists/oss-security/2024/12/17/4","http://www.openwall.com/lists/oss-security/2024/12/18/2","https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html","https://security.netapp.com/advisory/ntap-20250103-0003/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50379","description":"Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration).\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97.\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.\n\nUsers are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.13"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3712","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3712","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.13"],"available":[{"date":"2021-08-24","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3712","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3712","date":"2026-10-08","epss":0.50445,"percentile":0.98887}],"risk":25.222499999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3712"},"relatedVulnerabilities":[{"id":"CVE-2021-3712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3712","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3712","date":"2026-10-08","epss":0.50445,"percentile":0.98887}],"urls":["http://www.openwall.com/lists/oss-security/2021/08/26/2","https://cert-portal.siemens.com/productcert/pdf/ssa-244969.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=94d23fcff9b2a7a8368dfe52214d5c2569882c11","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ccb0a11145ee72b042d10593a64eaf9e8a55ec12","https://kc.mcafee.com/corporate/index?page=content&id=SB10366","https://lists.apache.org/thread.html/r18995de860f0e63635f3008fd2a6aca82394249476d21691e7c59c9e%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rad5d9f83f0d11fb3f8bb148d179b8a9ad7c6a17f18d70e5805a713d1%40%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/09/msg00014.html","https://lists.debian.org/debian-lts-announce/2021/09/msg00021.html","https://security.gentoo.org/glsa/202209-02","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20210827-0010/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-4963","https://www.openssl.org/news/secadv/20210824.txt","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-16","https://www.tenable.com/security/tns-2022-02","https://cert-portal.siemens.com/productcert/html/ssa-019200.html","https://cert-portal.siemens.com/productcert/html/ssa-028723.html","https://cert-portal.siemens.com/productcert/html/ssa-244969.html","https://cert-portal.siemens.com/productcert/html/ssa-389290.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3712","description":"ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL's own \"d2i\" functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the \"data\" and \"length\" fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the \"data\" field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the application instead of loading it via the OpenSSL parsing functions, and the certificate contains non NUL terminated ASN1_STRING structures). It can also occur in the X509_get1_email(), X509_REQ_get1_email() and X509_get1_ocsp() functions. If a malicious actor can cause an application to directly construct an ASN1_STRING and then process it through one of the affected OpenSSL functions then this issue could be hit. This might result in a crash (causing a Denial of Service attack). It could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext). Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k). Fixed in OpenSSL 1.0.2za (Affected 1.0.2-1.0.2y)."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-3712","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3712","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.13"],"available":[{"date":"2021-08-24","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3712","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3712","date":"2026-10-08","epss":0.50445,"percentile":0.98887}],"risk":25.222499999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3712"},"relatedVulnerabilities":[{"id":"CVE-2021-3712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3712","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3712","date":"2026-10-08","epss":0.50445,"percentile":0.98887}],"urls":["http://www.openwall.com/lists/oss-security/2021/08/26/2","https://cert-portal.siemens.com/productcert/pdf/ssa-244969.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=94d23fcff9b2a7a8368dfe52214d5c2569882c11","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ccb0a11145ee72b042d10593a64eaf9e8a55ec12","https://kc.mcafee.com/corporate/index?page=content&id=SB10366","https://lists.apache.org/thread.html/r18995de860f0e63635f3008fd2a6aca82394249476d21691e7c59c9e%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rad5d9f83f0d11fb3f8bb148d179b8a9ad7c6a17f18d70e5805a713d1%40%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/09/msg00014.html","https://lists.debian.org/debian-lts-announce/2021/09/msg00021.html","https://security.gentoo.org/glsa/202209-02","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20210827-0010/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-4963","https://www.openssl.org/news/secadv/20210824.txt","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-16","https://www.tenable.com/security/tns-2022-02","https://cert-portal.siemens.com/productcert/html/ssa-019200.html","https://cert-portal.siemens.com/productcert/html/ssa-028723.html","https://cert-portal.siemens.com/productcert/html/ssa-244969.html","https://cert-portal.siemens.com/productcert/html/ssa-389290.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3712","description":"ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL's own \"d2i\" functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the \"data\" and \"length\" fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the \"data\" field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the application instead of loading it via the OpenSSL parsing functions, and the certificate contains non NUL terminated ASN1_STRING structures). It can also occur in the X509_get1_email(), X509_REQ_get1_email() and X509_get1_ocsp() functions. If a malicious actor can cause an application to directly construct an ASN1_STRING and then process it through one of the affected OpenSSL functions then this issue could be hit. This might result in a crash (causing a Denial of Service attack). It could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext). Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k). Fixed in OpenSSL 1.0.2za (Affected 1.0.2-1.0.2y)."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4w82-r329-3q67","versionConstraint":">=2.9.0,<=2.9.10.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4w82-r329-3q67","fix":{"state":"fixed","versions":["2.9.10.3"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8840","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8840","date":"2026-10-08","epss":0.26587,"percentile":0.97974}],"risk":24.991780000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-8840","https://github.com/FasterXML/jackson-databind/issues/2620","https://github.com/FasterXML/jackson-databind/commit/914e7c9f2cb8ce66724bf26a72adc7e958992497","https://lists.apache.org/thread.html/r078e68a926ea6be12e8404e47f45aabf04bb4668e8265c0de41db6db@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r319f19c74e06c201b9d4e8b282a4e4b2da6dcda022fb46f007dd00d3@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r3539bd3a377991217d724879d239e16e86001c54160076408574e1da@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r3d20a2660b36551fd8257d479941782af4a7169582449fac1704bde2@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r428d068b2a4923f1a5a4f5fc6381b95205cfe7620169d16db78e9c71@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r46bebdeb59b8b7212d63a010ca445a9f5c4e9d64dcf693cab6f399d3@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r6fdd4c61a09a0c89f581b4ddb3dc6f154ab0c705fcfd0a7358b2e4e5@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r8170007fd9b263d65b37d92a7b5d7bc357aedbb113a32838bc4a9485@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9ecf211c22760b00967ebe158c6ed7dba9142078e2a630ab8904a5b7@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rac5ee5d686818be7e7c430d35108ee01a88aae54f832d32f62431fd1@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb43f9a65150948a6bebd3cb77ee3e105d40db2820fd547528f4e7f89@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb5eedf90ba3633e171a2ffdfe484651c9490dc5df74c8a29244cbc0e@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdf8d389271a291dde3b2f99c36918d6cb1e796958af626cc140fee23@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re7326b8655eab931f2a9ce074fd9a1a51b5db11456bee9b48e1e170c@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re8ae2670ec456ef1c5a2a661a2838ab2cd00e9efa1e88c069f546f21@%3Ccommits.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/02/msg00020.html","https://lists.apache.org/thread.html/r65ee95fa09c831843bac81eaa582fdddc2b6119912a72d1c83a9b882@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r1c09b9551f6953dbeca190a4c4b78198cdbb9825fce36f96fe3d8218@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r1efc776fc6ce3387593deaa94bbdd296733b1b01408a39c8d1ab9e0e@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r2fa8046bd47fb407ca09b5107a80fa6147ba4ebe879caae5c98b7657@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r446646c5588b10f5e02409ad580b12f314869009cdfbf844ca395cec@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r5d8bea8e9d17b6efcf4a0e4e194e91ef46a99f505777a31a60da2b38@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r7762d69e85c58d6948823424017ef4c08f47de077644277fa18cc116@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r7e5c10534ed06bf805473ac85e8412fe3908a8fa4cabf5027bf11220@%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r8e96c340004b7898cad3204ea51280ef6e4b553a684e1452bf1b18b1@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r94930e39b60fff236160c1c4110fe884dc093044b067aa5fc98d7ee1@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r9e59ebaf76fd00b2fa3ff5ebf18fe075ca9f4376216612c696f76718@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/ra275f29615f35d5b40106d1582a41e5388b2a5131564e9e01a572987@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rb73708bf714ed6dbc1212da082e7703e586077f0c92f3940b2e82caf@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rb99c7321eba5d4c907beec46675d52827528b738cfafd48eb4d862f1@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc068e824654c4b8bd4f2490bec869e29edbfcd5dfe02d47cbf7433b2@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc717fd6c65190f4e592345713f9ef0723fb7d71f624caa2a17caa26a@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rcc72b497e3dff2dc62ec9b89ceb90bc4e1b14fc56c3c252a6fcbb013@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rdea588d4a0ebf9cb7ce8c3a8f18d0d306507c4f8ba178dd3d20207b8@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rdf311f13e6356297e0ffe74397fdd25a3687b0a16e687c3ff5b834d8@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rf28ab6f224b48452afd567dfffb705fbda0fdbbf6535f6bc69d47e91@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rfc1ccfe89332155b72ce17f13a2701d3e7b9ec213324ceb90e79a28a@%3Cdev.ranger.apache.org%3E","https://security.netapp.com/advisory/ntap-20200327-0002/","https://www.oracle.com/security-alerts/cpuapr2020.html","http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200610-01-fastjason-en","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/74aba4042fce35ee0b91bd2847e788c10040d78b","https://github.com/FasterXML/jackson-databind/commit/9bb52c7122271df75435ec7e66ecf6b02b1ee14f"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4w82-r329-3q67","description":"Deserialization of Untrusted Data in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-8840","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8840","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8840","date":"2026-10-08","epss":0.26587,"percentile":0.97974}],"urls":["http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200610-01-fastjason-en","https://github.com/FasterXML/jackson-databind/issues/2620","https://lists.apache.org/thread.html/r078e68a926ea6be12e8404e47f45aabf04bb4668e8265c0de41db6db%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/r1c09b9551f6953dbeca190a4c4b78198cdbb9825fce36f96fe3d8218%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r1efc776fc6ce3387593deaa94bbdd296733b1b01408a39c8d1ab9e0e%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r2fa8046bd47fb407ca09b5107a80fa6147ba4ebe879caae5c98b7657%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r319f19c74e06c201b9d4e8b282a4e4b2da6dcda022fb46f007dd00d3%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r3539bd3a377991217d724879d239e16e86001c54160076408574e1da%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r3d20a2660b36551fd8257d479941782af4a7169582449fac1704bde2%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r428d068b2a4923f1a5a4f5fc6381b95205cfe7620169d16db78e9c71%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r446646c5588b10f5e02409ad580b12f314869009cdfbf844ca395cec%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r46bebdeb59b8b7212d63a010ca445a9f5c4e9d64dcf693cab6f399d3%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r5d8bea8e9d17b6efcf4a0e4e194e91ef46a99f505777a31a60da2b38%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r65ee95fa09c831843bac81eaa582fdddc2b6119912a72d1c83a9b882%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r6fdd4c61a09a0c89f581b4ddb3dc6f154ab0c705fcfd0a7358b2e4e5%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r7762d69e85c58d6948823424017ef4c08f47de077644277fa18cc116%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r7e5c10534ed06bf805473ac85e8412fe3908a8fa4cabf5027bf11220%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r8170007fd9b263d65b37d92a7b5d7bc357aedbb113a32838bc4a9485%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r8e96c340004b7898cad3204ea51280ef6e4b553a684e1452bf1b18b1%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r94930e39b60fff236160c1c4110fe884dc093044b067aa5fc98d7ee1%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r9e59ebaf76fd00b2fa3ff5ebf18fe075ca9f4376216612c696f76718%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r9ecf211c22760b00967ebe158c6ed7dba9142078e2a630ab8904a5b7%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra275f29615f35d5b40106d1582a41e5388b2a5131564e9e01a572987%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rac5ee5d686818be7e7c430d35108ee01a88aae54f832d32f62431fd1%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb43f9a65150948a6bebd3cb77ee3e105d40db2820fd547528f4e7f89%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb5eedf90ba3633e171a2ffdfe484651c9490dc5df74c8a29244cbc0e%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb73708bf714ed6dbc1212da082e7703e586077f0c92f3940b2e82caf%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rb99c7321eba5d4c907beec46675d52827528b738cfafd48eb4d862f1%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc068e824654c4b8bd4f2490bec869e29edbfcd5dfe02d47cbf7433b2%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc717fd6c65190f4e592345713f9ef0723fb7d71f624caa2a17caa26a%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rcc72b497e3dff2dc62ec9b89ceb90bc4e1b14fc56c3c252a6fcbb013%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rdea588d4a0ebf9cb7ce8c3a8f18d0d306507c4f8ba178dd3d20207b8%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rdf311f13e6356297e0ffe74397fdd25a3687b0a16e687c3ff5b834d8%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rdf8d389271a291dde3b2f99c36918d6cb1e796958af626cc140fee23%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re7326b8655eab931f2a9ce074fd9a1a51b5db11456bee9b48e1e170c%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re8ae2670ec456ef1c5a2a661a2838ab2cd00e9efa1e88c069f546f21%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rf28ab6f224b48452afd567dfffb705fbda0fdbbf6535f6bc69d47e91%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rfc1ccfe89332155b72ce17f13a2701d3e7b9ec213324ceb90e79a28a%40%3Cdev.ranger.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/02/msg00020.html","https://security.netapp.com/advisory/ntap-20200327-0002/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8840","description":"FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-5436","versionConstraint":"< 7.58.0-2ubuntu3.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-5436","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.7"],"available":[{"date":"2019-05-22","kind":"advisory","version":"7.58.0-2ubuntu3.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5436","cwe":"CWE-122","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2019-5436","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5436","date":"2026-10-08","epss":0.49739,"percentile":0.9887}],"risk":24.8695,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5436"},"relatedVulnerabilities":[{"id":"CVE-2019-5436","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5436","cwe":"CWE-122","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2019-5436","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5436","date":"2026-10-08","epss":0.49739,"percentile":0.9887}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00008.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00017.html","http://www.openwall.com/lists/oss-security/2019/09/11/6","https://curl.haxx.se/docs/CVE-2019-5436.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SMG3V4VTX2SE3EW3HQTN3DDLQBTORQC2/","https://seclists.org/bugtraq/2020/Feb/36","https://security.gentoo.org/glsa/202003-29","https://security.netapp.com/advisory/ntap-20190606-0004/","https://support.f5.com/csp/article/K55133295","https://support.f5.com/csp/article/K55133295?utm_source=f5support&amp%3Butm_medium=RSS","https://www.debian.org/security/2020/dsa-4633","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5436","description":"A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-5436","versionConstraint":"< 7.58.0-2ubuntu3.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-5436","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.7"],"available":[{"date":"2019-05-22","kind":"advisory","version":"7.58.0-2ubuntu3.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5436","cwe":"CWE-122","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2019-5436","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5436","date":"2026-10-08","epss":0.49739,"percentile":0.9887}],"risk":24.8695,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5436"},"relatedVulnerabilities":[{"id":"CVE-2019-5436","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5436","cwe":"CWE-122","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2019-5436","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5436","date":"2026-10-08","epss":0.49739,"percentile":0.9887}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00008.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00017.html","http://www.openwall.com/lists/oss-security/2019/09/11/6","https://curl.haxx.se/docs/CVE-2019-5436.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SMG3V4VTX2SE3EW3HQTN3DDLQBTORQC2/","https://seclists.org/bugtraq/2020/Feb/36","https://security.gentoo.org/glsa/202003-29","https://security.netapp.com/advisory/ntap-20190606-0004/","https://support.f5.com/csp/article/K55133295","https://support.f5.com/csp/article/K55133295?utm_source=f5support&amp%3Butm_medium=RSS","https://www.debian.org/security/2020/dsa-4633","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5436","description":"A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.9.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mph4-vhrx-mv67","versionConstraint":">=2.9.0,<2.9.9.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mph4-vhrx-mv67","fix":{"state":"fixed","versions":["2.9.9.1"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.9.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12384","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-12384","date":"2026-10-08","epss":0.45205,"percentile":0.98755}],"risk":24.636725000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-12384","https://doyensec.com/research.html","https://github.com/FasterXML/jackson-databind/compare/74b90a4...a977aad","https://lists.debian.org/debian-lts-announce/2019/06/msg00019.html","https://access.redhat.com/errata/RHSA-2019:1820","https://access.redhat.com/errata/RHSA-2019:2720","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:2998","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2019:3292","https://access.redhat.com/errata/RHSA-2019:3297","https://access.redhat.com/errata/RHSA-2019:3901","https://access.redhat.com/errata/RHSA-2019:4352","https://blog.doyensec.com/2019/07/22/jackson-gadgets.html","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef@%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/e0733058c0366b703e6757d8d2a7a04b943581f659e9c271f0841dfe@%3Cnotifications.geode.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://seclists.org/bugtraq/2019/Oct/6","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/issues/2334","https://github.com/FasterXML/jackson-databind/commit/c9ef4a10d6f6633cf470d6a469514b68fa2be234","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC","https://security.netapp.com/advisory/ntap-20190703-0002"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mph4-vhrx-mv67","description":"Deserialization of Untrusted Data in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-12384","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12384","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-12384","date":"2026-10-08","epss":0.45205,"percentile":0.98755}],"urls":["https://access.redhat.com/errata/RHSA-2019:1820","https://access.redhat.com/errata/RHSA-2019:2720","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:2998","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2019:3292","https://access.redhat.com/errata/RHSA-2019:3297","https://access.redhat.com/errata/RHSA-2019:3901","https://access.redhat.com/errata/RHSA-2019:4352","https://blog.doyensec.com/2019/07/22/jackson-gadgets.html","https://doyensec.com/research.html","https://github.com/FasterXML/jackson-databind/compare/74b90a4...a977aad","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef%40%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/e0733058c0366b703e6757d8d2a7a04b943581f659e9c271f0841dfe%40%3Cnotifications.geode.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20190703-0002/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12384","description":"FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h3gc-qfqq-6h8f","versionConstraint":">=8.5.0,<=8.5.100 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-h3gc-qfqq-6h8f","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48988","cwe":"CWE-770","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-48988","date":"2026-10-08","epss":0.30515,"percentile":0.982}],"risk":23.801699999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-48988","https://lists.apache.org/thread/nzkqsok8t42qofgqfmck536mtyzygp18","https://github.com/apache/tomcat/commit/2b0ab14fb55d4edc896e5f1817f2ab76f714ae5e","https://github.com/apache/tomcat/commit/cdde8e655bc1c5c60a07efd216251d77c52fd7f6","https://github.com/apache/tomcat/commit/ee8042ffce4cb9324dfd79efda5984f37bbb6910","https://tomcat.apache.org/security-10.html","https://tomcat.apache.org/security-11.html","https://tomcat.apache.org/security-9.html","http://www.openwall.com/lists/oss-security/2025/06/16/1","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h3gc-qfqq-6h8f","description":"Apache Tomcat - DoS in multipart upload"},"relatedVulnerabilities":[{"id":"CVE-2025-48988","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48988","cwe":"CWE-770","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-48988","date":"2026-10-08","epss":0.30515,"percentile":0.982}],"urls":["https://lists.apache.org/thread/nzkqsok8t42qofgqfmck536mtyzygp18","http://www.openwall.com/lists/oss-security/2025/06/16/1","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-48988","description":"Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions \nmay also be affected.\n\n\nUsers are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue."}]},{"artifact":{"id":"c6727d7037f24912","cpes":["cpe:2.3:a:libdb5.3:libdb5.3:5.3.28-13.1ubuntu1:*:*:*:*:*:*:*"],"name":"libdb5.3","purl":"pkg:deb/ubuntu/libdb5.3@5.3.28-13.1ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=db5.3","type":"deb","version":"5.3.28-13.1ubuntu1","language":"","licenses":["sha256:b3bbc6fbb3f2a0e6a487e953eb8c3cc4bdb6f4150f7f51d20b1e9a3c8ef92d3d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libdb5.3/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libdb5.3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libdb5.3:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libdb5.3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"db5.3"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.3.28-13.1ubuntu1.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-8457","versionConstraint":"< 5.3.28-13.1ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"db5.3","version":"5.3.28-13.1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-8457","fix":{"state":"fixed","versions":["5.3.28-13.1ubuntu1.1"],"available":[{"date":"2019-06-04","kind":"advisory","version":"5.3.28-13.1ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-8457","cwe":"CWE-125","type":"Secondary","source":"cve@checkpoint.com"},{"cve":"CVE-2019-8457","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-8457","date":"2026-10-08","epss":0.45426,"percentile":0.98761}],"risk":22.713,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-8457"},"relatedVulnerabilities":[{"id":"CVE-2019-8457","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-8457","cwe":"CWE-125","type":"Secondary","source":"cve@checkpoint.com"},{"cve":"CVE-2019-8457","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-8457","date":"2026-10-08","epss":0.45426,"percentile":0.98761}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00074.html","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPKYSWCOM3CL66RI76TYVIG6TJ263RXH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SJPFGA45DI4F5MCF2OAACGH3HQOF4G3M/","https://security.netapp.com/advisory/ntap-20190606-0002/","https://usn.ubuntu.com/4004-1/","https://usn.ubuntu.com/4004-2/","https://usn.ubuntu.com/4019-1/","https://usn.ubuntu.com/4019-2/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.sqlite.org/releaselog/3_28_0.html","https://www.sqlite.org/src/info/90acdbfce9c08858"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-8457","description":"SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables."}]},{"artifact":{"id":"0b1c74783f88c915","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.22.0-1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-8457","versionConstraint":"< 3.22.0-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-8457","fix":{"state":"fixed","versions":["3.22.0-1ubuntu0.1"],"available":[{"date":"2019-06-19","kind":"advisory","version":"3.22.0-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-8457","cwe":"CWE-125","type":"Secondary","source":"cve@checkpoint.com"},{"cve":"CVE-2019-8457","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-8457","date":"2026-10-08","epss":0.45426,"percentile":0.98761}],"risk":22.713,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-8457"},"relatedVulnerabilities":[{"id":"CVE-2019-8457","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-8457","cwe":"CWE-125","type":"Secondary","source":"cve@checkpoint.com"},{"cve":"CVE-2019-8457","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-8457","date":"2026-10-08","epss":0.45426,"percentile":0.98761}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00074.html","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPKYSWCOM3CL66RI76TYVIG6TJ263RXH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SJPFGA45DI4F5MCF2OAACGH3HQOF4G3M/","https://security.netapp.com/advisory/ntap-20190606-0002/","https://usn.ubuntu.com/4004-1/","https://usn.ubuntu.com/4004-2/","https://usn.ubuntu.com/4019-1/","https://usn.ubuntu.com/4019-2/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.sqlite.org/releaselog/3_28_0.html","https://www.sqlite.org/src/info/90acdbfce9c08858"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-8457","description":"SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables."}]},{"artifact":{"id":"c1829cdc68f9166a","cpes":["cpe:2.3:a:org.springframework:spring-expression:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_expression:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-expression:spring-expression:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-expression:spring_expression:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_expression:spring-expression:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_expression:spring_expression:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-expression:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_expression:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-expression:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_expression:5.0.8.RELEASE:*:*:*:*:*:*:*"],"name":"spring-expression","purl":"pkg:maven/org.springframework/spring-expression@5.0.8.RELEASE","type":"java-archive","version":"5.0.8.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-expression-5.0.8.RELEASE.jar","manifestName":"","pomArtifactID":"spring-expression","archiveDigests":[{"value":"f23158f22c917df2cddf2ecebc398a9e95f95fae","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-expression-5.0.8.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.2.20.RELEASE"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-558x-2xjg-6232","versionConstraint":"<5.2.20.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-expression","version":"5.0.8.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-558x-2xjg-6232","fix":{"state":"fixed","versions":["5.2.20.RELEASE"],"available":[{"date":"2023-03-29","kind":"first-observed","version":"5.2.20.RELEASE"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22950","cwe":"CWE-770","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22950","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22950","date":"2026-10-08","epss":0.36081,"percentile":0.98442}],"risk":20.746575,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22950","https://tanzu.vmware.com/security/cve-2022-22950","https://github.com/spring-projects/spring-framework/issues/28145","https://github.com/spring-projects/spring-framework/issues/28257","https://github.com/spring-projects/spring-framework/commit/83ac65915871067c39a4fb255e0d484c785c0c11","https://github.com/spring-projects/spring-framework/releases/tag/v5.2.20.RELEASE","https://github.com/spring-projects/spring-framework/releases/tag/v5.3.17"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-558x-2xjg-6232","description":"Allocation of Resources Without Limits or Throttling in Spring Framework"},"relatedVulnerabilities":[{"id":"CVE-2022-22950","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22950","cwe":"CWE-770","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22950","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22950","date":"2026-10-08","epss":0.36081,"percentile":0.98442}],"urls":["https://tanzu.vmware.com/security/cve-2022-22950"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22950","description":"n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition."}]},{"artifact":{"id":"f2b3aae4ffb91c19","cpes":["cpe:2.3:a:org.yaml.snakeyaml:snakeyaml:1.19:*:*:*:*:*:*:*","cpe:2.3:a:snakeyaml:snakeyaml:1.19:*:*:*:*:*:*:*","cpe:2.3:a:org.yaml:snakeyaml:1.19:*:*:*:*:*:*:*","cpe:2.3:a:yaml:snakeyaml:1.19:*:*:*:*:*:*:*"],"name":"snakeyaml","purl":"pkg:maven/org.yaml/snakeyaml@1.19","type":"java-archive","version":"1.19","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.yaml","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/snakeyaml-1.19.jar","manifestName":"","pomArtifactID":"snakeyaml","archiveDigests":[{"value":"2d998d3d674b172a588e54ab619854d073f555b5","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/snakeyaml-1.19.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rvwf-54qp-4r6v","versionConstraint":"<1.26 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.yaml:snakeyaml","version":"1.19"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-rvwf-54qp-4r6v","fix":{"state":"fixed","versions":["1.26"],"available":[{"date":"2021-06-05","kind":"first-observed","version":"1.26"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-18640","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18640","date":"2026-10-08","epss":0.26723,"percentile":0.97984}],"risk":20.04225,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2017-18640","https://bitbucket.org/asomov/snakeyaml/commits/da11ddbd91c1f8392ea932b37fa48110fa54ed8c","https://bitbucket.org/asomov/snakeyaml/issues/377/allow-configuration-for-preventing-billion","https://bitbucket.org/asomov/snakeyaml/wiki/Billion%20laughs%20attack","https://bitbucket.org/asomov/snakeyaml/wiki/Changes","https://lists.apache.org/thread.html/r1058e7646988394de6a3fd0857ea9b1ee0de14d7bb28fee5ff782457@%3Ccommits.atlas.apache.org%3E","https://lists.apache.org/thread.html/r154090b871cf96d985b90864442d84eb027c72c94bc3f0a5727ba2d1@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r1703a402f30c8a2ee409f8c6f393e95a63f8c952cc9ee5bf9dd586dc@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r191ceadb1b883357384981848dfa5235cb02a90070c553afbaf9b3d9@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r1aab47b48a757c70e40fc0bcb1fcf1a3951afa6a17aee7cd66cf79f8@%3Ccommon-commits.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r1dfac8b6a7097bcb4979402bbb6e2f8c36d0d9001e3018717eb22b7e@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r1ffce2ed3017e9964f03ad2c539d69e49144fc8e9bf772d641612f98@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r20350031c60a77b45e0eded33e9b3e9cb0cbfc5e24e1c63bf264df12@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r22ac2aa053b7d9c6b75a49db78125c9316499668d0f4a044f3402e2f@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r28c9009a48d52cf448f8b02cd823da0f8601d2dff4d66f387a35f1e0@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r2a5b84fdf59042dc398497e914b5bb1aed77328320b1438144ae1953@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r2b05744c0c2867daa5d1a96832965b7d6220328b0ead06c22a6e7854@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r2db207a2431a5e9e95e899858ab1f5eabd9bcc790a6ca7193ae07e94@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r436988d2cfe8a770ae361c82b181c5b2bf48a249bad84d8a55a3b46e@%3Cdev.phoenix.apache.org%3E","https://lists.apache.org/thread.html/r4c682fb8cf69dd14162439656a6ebdf42ea6ad0e4edba95907ea3f14@%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/r4d7f37da1bc2df90a5a0f56eb7629b5ea131bfe11eeeb4b4c193f64a@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r5510f0125ba409fc1cabd098ab8b457741e5fa314cbd0e61e4339422@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r55d807f31e64a080c54455897c20b1667ec792e5915132c7b7750533@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r56805265475919252ba7fc10123f15b91097f3009bae86476624ca25@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r643ba53f002ae59068f9352fe1d82e1b6f375387ffb776f13efe8fda@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r666f29a7d0e1f98fa1425ca01efcfa86e6e3856e01d300828aa7c6ea@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r6c91e52b3cc9f4e64afe0f34f20507143fd1f756d12681a56a9b38da@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r6d54c2da792c74cc14b9b7665ea89e144c9e238ed478d37fd56292e6@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r72a3588d62b2de1361dc9648f5d355385735e47f7ba49d089b0e680d@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r7ce3de03facf7e7f3e24fc25d26d555818519dafdb20f29398a3414b@%3Cdev.phoenix.apache.org%3E","https://lists.apache.org/thread.html/r8464b6ec951aace8c807bac9ea526d4f9e3116aa16d38be06f7c6524@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r8b57c57cffa01e418868a3c7535b987635ff1fb5ab534203bfa2d64a@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r900e020760c89f082df1c6e0d46320eba721e4e47bb9eb521e68cd95@%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/raebd2019b3da8c2f90f31e8b203b45353f78770ca93bfe5376f5532e@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb0e033d5ec8233360203431ad96580cf2ec56f47d9a425d894e279c2@%3Cpr.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rb34d8d3269ad47a1400f5a1a2d8310e13a80b6576ebd7f512144198d@%3Ccommon-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb5c33d0069c927fae16084f0605895b98d231d7c48527bcb822ac48c@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rb7b28ac741e32dd5edb2c22485d635275bead7290b056ee56baf8ce0@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/rbaa1f513d903c89a08267c91d86811fa5bcc82e0596b6142c5cea7ea@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rc3211c71f7e0973a1825d1988a3921288c06cd9d793eae97ecd34948@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rcb2a7037366c58bac6aec6ce3df843a11ef97ae4eb049f05f410eaa5@%3Ccommon-commits.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rcb4b61dbe2ed1c7a88781a9aff5a9e7342cc7ed026aec0418ee67596@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rce5c93bba6e815fb62ad38e28ca1943b3019af1eddeb06507ad4e11a@%3Ccommits.atlas.apache.org%3E","https://lists.apache.org/thread.html/rd582c64f66c354240290072f340505f5d026ca944ec417226bb0272e@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/re791a854001ec1f79cd4f47328b270e7a1d9d7056debb8f16d962722@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/re851bbfbedd47c690b6e01942acb98ee08bd00df1a94910b905bc8cd@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/reb1751562ee5146d3aca654a2df76a2c13d8036645ce69946f9c219e@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/recfe569f4f260328b0036f1c82b2956e864d519ab941a5e75d0d832d@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rf95bebee6dfcc55067cebe8482bd31e6f481d9f74ba8e03f860c3ec7@%3Ccommits.cassandra.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CKN7VGIKTYBCAKYBRG55QHXAY5UDZ7HA/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PTVJC54XGX26UJVVYCXZ7D25X3R5T2G6/","https://mvnrepository.com/artifact/org.yaml/snakeyaml/1.25/usages","https://www.oracle.com/security-alerts/cpuApr2021.html","https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe@%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r16ae4e529401b75a1f5aa462b272b31bf2a108236f882f06fddc14bc@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r182e9cf6f3fb22b9be0cac4ff0685199741d2ab6e9a4e27a3693c224@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r465d2553a31265b042cf5457ef649b71e0722ab89b6ea94a5d59529b@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rdd34c0479587e32a656d976649409487d51ca0d296b3e26b6b89c3f5@%3Ccommon-commits.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rfe0aab6c3bebbd9cbfdedb65ff3fdf420714bcb8acdfd346077e1263@%3Ccommon-commits.hadoop.apache.org%3E","https://bitbucket.org/snakeyaml/snakeyaml/issues/377","https://bitbucket.org/snakeyaml/snakeyaml/wiki/Changes","https://security.gentoo.org/glsa/202305-28"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rvwf-54qp-4r6v","description":"SnakeYAML Entity Expansion during load operation"},"relatedVulnerabilities":[{"id":"CVE-2017-18640","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-18640","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18640","date":"2026-10-08","epss":0.26723,"percentile":0.97984}],"urls":["https://bitbucket.org/asomov/snakeyaml/issues/377/allow-configuration-for-preventing-billion","https://bitbucket.org/asomov/snakeyaml/wiki/Billion%20laughs%20attack","https://bitbucket.org/snakeyaml/snakeyaml/issues/377","https://bitbucket.org/snakeyaml/snakeyaml/wiki/Changes","https://lists.apache.org/thread.html/r1058e7646988394de6a3fd0857ea9b1ee0de14d7bb28fee5ff782457%40%3Ccommits.atlas.apache.org%3E","https://lists.apache.org/thread.html/r154090b871cf96d985b90864442d84eb027c72c94bc3f0a5727ba2d1%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r16ae4e529401b75a1f5aa462b272b31bf2a108236f882f06fddc14bc%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r1703a402f30c8a2ee409f8c6f393e95a63f8c952cc9ee5bf9dd586dc%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r182e9cf6f3fb22b9be0cac4ff0685199741d2ab6e9a4e27a3693c224%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r191ceadb1b883357384981848dfa5235cb02a90070c553afbaf9b3d9%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r1aab47b48a757c70e40fc0bcb1fcf1a3951afa6a17aee7cd66cf79f8%40%3Ccommon-commits.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r1dfac8b6a7097bcb4979402bbb6e2f8c36d0d9001e3018717eb22b7e%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r1ffce2ed3017e9964f03ad2c539d69e49144fc8e9bf772d641612f98%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r20350031c60a77b45e0eded33e9b3e9cb0cbfc5e24e1c63bf264df12%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r22ac2aa053b7d9c6b75a49db78125c9316499668d0f4a044f3402e2f%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r28c9009a48d52cf448f8b02cd823da0f8601d2dff4d66f387a35f1e0%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r2a5b84fdf59042dc398497e914b5bb1aed77328320b1438144ae1953%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r2b05744c0c2867daa5d1a96832965b7d6220328b0ead06c22a6e7854%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r2db207a2431a5e9e95e899858ab1f5eabd9bcc790a6ca7193ae07e94%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r436988d2cfe8a770ae361c82b181c5b2bf48a249bad84d8a55a3b46e%40%3Cdev.phoenix.apache.org%3E","https://lists.apache.org/thread.html/r465d2553a31265b042cf5457ef649b71e0722ab89b6ea94a5d59529b%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r4c682fb8cf69dd14162439656a6ebdf42ea6ad0e4edba95907ea3f14%40%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/r4d7f37da1bc2df90a5a0f56eb7629b5ea131bfe11eeeb4b4c193f64a%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r5510f0125ba409fc1cabd098ab8b457741e5fa314cbd0e61e4339422%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r55d807f31e64a080c54455897c20b1667ec792e5915132c7b7750533%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r56805265475919252ba7fc10123f15b91097f3009bae86476624ca25%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r643ba53f002ae59068f9352fe1d82e1b6f375387ffb776f13efe8fda%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r666f29a7d0e1f98fa1425ca01efcfa86e6e3856e01d300828aa7c6ea%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r6c91e52b3cc9f4e64afe0f34f20507143fd1f756d12681a56a9b38da%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r6d54c2da792c74cc14b9b7665ea89e144c9e238ed478d37fd56292e6%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r72a3588d62b2de1361dc9648f5d355385735e47f7ba49d089b0e680d%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r7ce3de03facf7e7f3e24fc25d26d555818519dafdb20f29398a3414b%40%3Cdev.phoenix.apache.org%3E","https://lists.apache.org/thread.html/r8464b6ec951aace8c807bac9ea526d4f9e3116aa16d38be06f7c6524%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r8b57c57cffa01e418868a3c7535b987635ff1fb5ab534203bfa2d64a%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r900e020760c89f082df1c6e0d46320eba721e4e47bb9eb521e68cd95%40%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/raebd2019b3da8c2f90f31e8b203b45353f78770ca93bfe5376f5532e%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb0e033d5ec8233360203431ad96580cf2ec56f47d9a425d894e279c2%40%3Cpr.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rb34d8d3269ad47a1400f5a1a2d8310e13a80b6576ebd7f512144198d%40%3Ccommon-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb5c33d0069c927fae16084f0605895b98d231d7c48527bcb822ac48c%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rb7b28ac741e32dd5edb2c22485d635275bead7290b056ee56baf8ce0%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/rbaa1f513d903c89a08267c91d86811fa5bcc82e0596b6142c5cea7ea%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rc3211c71f7e0973a1825d1988a3921288c06cd9d793eae97ecd34948%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rcb2a7037366c58bac6aec6ce3df843a11ef97ae4eb049f05f410eaa5%40%3Ccommon-commits.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rcb4b61dbe2ed1c7a88781a9aff5a9e7342cc7ed026aec0418ee67596%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rce5c93bba6e815fb62ad38e28ca1943b3019af1eddeb06507ad4e11a%40%3Ccommits.atlas.apache.org%3E","https://lists.apache.org/thread.html/rd582c64f66c354240290072f340505f5d026ca944ec417226bb0272e%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rdd34c0479587e32a656d976649409487d51ca0d296b3e26b6b89c3f5%40%3Ccommon-commits.hadoop.apache.org%3E","https://lists.apache.org/thread.html/re791a854001ec1f79cd4f47328b270e7a1d9d7056debb8f16d962722%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/re851bbfbedd47c690b6e01942acb98ee08bd00df1a94910b905bc8cd%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/reb1751562ee5146d3aca654a2df76a2c13d8036645ce69946f9c219e%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/recfe569f4f260328b0036f1c82b2956e864d519ab941a5e75d0d832d%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rf95bebee6dfcc55067cebe8482bd31e6f481d9f74ba8e03f860c3ec7%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rfe0aab6c3bebbd9cbfdedb65ff3fdf420714bcb8acdfd346077e1263%40%3Ccommon-commits.hadoop.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CKN7VGIKTYBCAKYBRG55QHXAY5UDZ7HA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PTVJC54XGX26UJVVYCXZ7D25X3R5T2G6/","https://mvnrepository.com/artifact/org.yaml/snakeyaml/1.25/usages","https://security.gentoo.org/glsa/202305-28","https://www.oracle.com/security-alerts/cpuApr2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-18640","description":"The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.55"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-53hp-jpwq-2jgq","versionConstraint":">=8.5.0,<8.5.55 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-53hp-jpwq-2jgq","fix":{"state":"fixed","versions":["8.5.55"],"available":[{"date":"2026-06-11","kind":"first-observed","version":"8.5.55"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-11996","date":"2026-10-08","epss":0.26699,"percentile":0.97981}],"risk":20.02425,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-11996","https://lists.apache.org/thread.html/r2529016c311ce9485e6f173446d469600fdfbb94dccadfcd9dfdac79@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3ea96d8f36dd404acce83df8aeb22a9e807d6c13ca9c5dec72f872cd@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r5541ef6b6b68b49f76fc4c45695940116da2bcbe0312ef204a00a2e0%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r5a4f80a6acc6607d61dae424b643b594c6188dd4e1eff04705c10db2@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r6c29801370a36c1a5159679269777ad0c73276d3015b8bbefea66e5c@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r74f5a8204efe574cbfcd95b2a16236fe95beb45c4d9fee3dc789dca9@%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r8f3d416c193bc9384a8a7dd368623d441f5fcaff1057115008100561@%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r8f7484589454638af527182ae55ef5b628ba00c05c5b11887c922fb1@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r93ca628ef3a4530dfe5ac49fddc795f0920a4b2a408b57a30926a42b@%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r9ad911fe49450ed9405827af0e7a74104041081ff91864b1f2546bbd@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/ra7092f7492569b39b04ec0decf52628ba86c51f15efb38f5853e2760@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rb4ee49ecc4c59620ffd5e66e84a17e526c2c3cfa95d0cd682d90d338@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rb820f1a2a02bf07414be12c653c2ab5321fd87b9bf6c5e635c53ff4b@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rc80b96b4b96618b2b7461cb90664a428cfd6605eea9f74e51b792542@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rea65d6ef2e45dd1c45faae83922042732866c7b88fa109b76c83db52@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/ref0339792ac6dac1dba83c071a727ad72380899bde60f6aaad4031b9@%3Cnotifications.ofbiz.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/07/msg00010.html","https://www.debian.org/security/2020/dsa-4727","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00072.html","https://github.com/apache/tomcat/commit/9434a44d3449d620b1be70206819f8275b4a7509","https://github.com/apache/tomcat/commit/9a0231683a77e2957cea0fdee88b193b30b0c976","https://usn.ubuntu.com/4596-1","https://security.netapp.com/advisory/ntap-20200709-0002","https://tomcat.apache.org/security-9.html","https://tomcat.apache.org/security-8.html","https://tomcat.apache.org/security-10.html","https://github.com/apache/tomcat/commit/c8acd2ab7371e39aeca7c306f3b5380f00afe552"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-53hp-jpwq-2jgq","description":"Uncontrolled Resource Consumption in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2020-11996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-11996","date":"2026-10-08","epss":0.26699,"percentile":0.97981}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00072.html","https://lists.apache.org/thread.html/r2529016c311ce9485e6f173446d469600fdfbb94dccadfcd9dfdac79%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3ea96d8f36dd404acce83df8aeb22a9e807d6c13ca9c5dec72f872cd%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r5541ef6b6b68b49f76fc4c45695940116da2bcbe0312ef204a00a2e0%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r5a4f80a6acc6607d61dae424b643b594c6188dd4e1eff04705c10db2%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r6c29801370a36c1a5159679269777ad0c73276d3015b8bbefea66e5c%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r74f5a8204efe574cbfcd95b2a16236fe95beb45c4d9fee3dc789dca9%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r8f3d416c193bc9384a8a7dd368623d441f5fcaff1057115008100561%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r8f7484589454638af527182ae55ef5b628ba00c05c5b11887c922fb1%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r93ca628ef3a4530dfe5ac49fddc795f0920a4b2a408b57a30926a42b%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r9ad911fe49450ed9405827af0e7a74104041081ff91864b1f2546bbd%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/ra7092f7492569b39b04ec0decf52628ba86c51f15efb38f5853e2760%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rb4ee49ecc4c59620ffd5e66e84a17e526c2c3cfa95d0cd682d90d338%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rb820f1a2a02bf07414be12c653c2ab5321fd87b9bf6c5e635c53ff4b%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rc80b96b4b96618b2b7461cb90664a428cfd6605eea9f74e51b792542%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rea65d6ef2e45dd1c45faae83922042732866c7b88fa109b76c83db52%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/ref0339792ac6dac1dba83c071a727ad72380899bde60f6aaad4031b9%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/07/msg00010.html","https://security.netapp.com/advisory/ntap-20200709-0002/","https://usn.ubuntu.com/4596-1/","https://www.debian.org/security/2020/dsa-4727","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-11996","description":"A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.3+7-1ubuntu2~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2684","versionConstraint":"< 11.0.3+7-1ubuntu2~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2684","fix":{"state":"fixed","versions":["11.0.3+7-1ubuntu2~18.04.1"],"available":[{"date":"2019-05-13","kind":"advisory","version":"11.0.3+7-1ubuntu2~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2684","date":"2026-10-08","epss":0.37618,"percentile":0.98505}],"risk":18.809,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2684"},"relatedVulnerabilities":[{"id":"CVE-2019-2684","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2684","date":"2026-10-08","epss":0.37618,"percentile":0.98505}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00007.html","http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00058.html","http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00059.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00013.html","http://www.openwall.com/lists/oss-security/2020/09/01/4","http://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:1146","https://access.redhat.com/errata/RHSA-2019:1163","https://access.redhat.com/errata/RHSA-2019:1164","https://access.redhat.com/errata/RHSA-2019:1165","https://access.redhat.com/errata/RHSA-2019:1166","https://access.redhat.com/errata/RHSA-2019:1238","https://access.redhat.com/errata/RHSA-2019:1325","https://access.redhat.com/errata/RHSA-2019:1518","https://lists.apache.org/thread.html/38a01302c92ae513910d8c851a2d111736565bd698be4e3af3e4c063%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/43530b91506e2e0c11cfbe691173f5df8c48f51b98262426d7493b67%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/71bd3e4e222479c266eaafc8d0c171ef5782a69b52f68df11b650ed7%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/c58d6c3b49c615916b163809f963a55421cac2264885739508e68108%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/f7f54b4888060d99f59993f006e25005a2b58db0c07ff866bdcd6f17%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r1fd117082b992e7d43c1286e966c285f98aa362e685695d999ff42f7%40%3Cuser.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r718e01f61b35409a4f7a3ccbc1cb5136a1558a9f9c2cb8d4ca9be1ce%40%3Cuser.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rab8d90d28f944d84e4d7852f355a25c89451ae02c2decc4d355a9cfc%40%3Cuser.cassandra.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rcd7544b24d8fc32b7950ec4c117052410b661babaa857fb1fc641152%40%3Cdev.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rcd7544b24d8fc32b7950ec4c117052410b661babaa857fb1fc641152%40%3Cuser.cassandra.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/05/msg00011.html","https://seclists.org/bugtraq/2019/May/75","https://security.gentoo.org/glsa/201908-10","https://support.f5.com/csp/article/K11175903?utm_source=f5support&amp%3Butm_medium=RSS","https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03959en_us","https://usn.ubuntu.com/3975-1/","https://www.debian.org/security/2019/dsa-4453"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2684","description":"Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-2398","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-2398","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2398","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-2398","date":"2026-10-08","epss":0.36081,"percentile":0.98442}],"risk":18.0405,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2398"},"relatedVulnerabilities":[{"id":"CVE-2024-2398","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2398","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-2398","date":"2026-10-08","epss":0.36081,"percentile":0.98442}],"urls":["http://seclists.org/fulldisclosure/2024/Jul/18","http://seclists.org/fulldisclosure/2024/Jul/19","http://seclists.org/fulldisclosure/2024/Jul/20","http://www.openwall.com/lists/oss-security/2024/03/27/3","https://curl.se/docs/CVE-2024-2398.html","https://curl.se/docs/CVE-2024-2398.json","https://hackerone.com/reports/2402845","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2D44YLAUFJU6BZ4XFG2FYV7SBKXB5IZ6/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GMD6UYKCCRCYETWQZUJ65ZRFULT6SHLI/","https://security.netapp.com/advisory/ntap-20240503-0009/","https://support.apple.com/kb/HT214118","https://support.apple.com/kb/HT214119","https://support.apple.com/kb/HT214120"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2398","description":"When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory.  Further, this error condition fails silently and is therefore not easily detected by an application."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-2398","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-2398","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2398","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-2398","date":"2026-10-08","epss":0.36081,"percentile":0.98442}],"risk":18.0405,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2398"},"relatedVulnerabilities":[{"id":"CVE-2024-2398","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2398","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-2398","date":"2026-10-08","epss":0.36081,"percentile":0.98442}],"urls":["http://seclists.org/fulldisclosure/2024/Jul/18","http://seclists.org/fulldisclosure/2024/Jul/19","http://seclists.org/fulldisclosure/2024/Jul/20","http://www.openwall.com/lists/oss-security/2024/03/27/3","https://curl.se/docs/CVE-2024-2398.html","https://curl.se/docs/CVE-2024-2398.json","https://hackerone.com/reports/2402845","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2D44YLAUFJU6BZ4XFG2FYV7SBKXB5IZ6/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GMD6UYKCCRCYETWQZUJ65ZRFULT6SHLI/","https://security.netapp.com/advisory/ntap-20240503-0009/","https://support.apple.com/kb/HT214118","https://support.apple.com/kb/HT214119","https://support.apple.com/kb/HT214120"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2398","description":"When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory.  Further, this error condition fails silently and is therefore not easily detected by an application."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p43x-xfjf-5jhr","versionConstraint":">=2.9.0,<2.9.10.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p43x-xfjf-5jhr","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9548","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-9548","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-9548","date":"2026-10-08","epss":0.18921,"percentile":0.97232}],"risk":17.78574,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-9548","https://github.com/FasterXML/jackson-databind/issues/2634","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6@%3Cissues.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097@%3Cissues.zookeeper.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/9f4e97019fb0dd836533d0b6198c88787e235ae2","https://github.com/FasterXML/jackson-databind/commit/1e64db6a2fad331f96c7363fda3bc5f3dffa25bb","https://security.netapp.com/advisory/ntap-20200904-0006"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p43x-xfjf-5jhr","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-9548","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9548","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-9548","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-9548","date":"2026-10-08","epss":0.18921,"percentile":0.97232}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2634","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200904-0006/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-9548","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core)."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q93h-jc49-78gg","versionConstraint":">=2.9.0,<2.9.10.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q93h-jc49-78gg","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9547","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-9547","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-9547","date":"2026-10-08","epss":0.18383,"percentile":0.97165}],"risk":17.28002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-9547","https://github.com/FasterXML/jackson-databind/issues/2634","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r742ef70d126548dcf7de5be5779355c9d76a9aec71d7a9ef02c6398a@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra3e90712f2d59f8cef03fa796f5adf163d32b81fe7b95385f21790e6@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd0e958d6d5c5ee16efed73314cd0e445c8dbb4bdcc80fc9d1d6c11fc@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/redbe4f1e21bf080f637cf9fbec47729750a2f443a919765360337428@%3Cnotifications.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.apache.org/thread.html/r4accb2e0de9679174efd3d113a059bab71ff3ec53e882790d21c1cc1@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc0d5d0f72da1ed6fc5e438b1ddb3fa090c73006b55f873cf845375ab@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097@%3Cissues.zookeeper.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://security.netapp.com/advisory/ntap-20200904-0006/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/9f4e97019fb0dd836533d0b6198c88787e235ae2"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q93h-jc49-78gg","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-9547","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9547","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-9547","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-9547","date":"2026-10-08","epss":0.18383,"percentile":0.97165}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2634","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r4accb2e0de9679174efd3d113a059bab71ff3ec53e882790d21c1cc1%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r742ef70d126548dcf7de5be5779355c9d76a9aec71d7a9ef02c6398a%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra3e90712f2d59f8cef03fa796f5adf163d32b81fe7b95385f21790e6%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc0d5d0f72da1ed6fc5e438b1ddb3fa090c73006b55f873cf845375ab%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd0e958d6d5c5ee16efed73314cd0e445c8dbb4bdcc80fc9d1d6c11fc%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/redbe4f1e21bf080f637cf9fbec47729750a2f443a919765360337428%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200904-0006/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-9547","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap)."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.19"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-32206","versionConstraint":"< 7.58.0-2ubuntu3.19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-32206","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.19"],"available":[{"date":"2022-06-27","kind":"advisory","version":"7.58.0-2ubuntu3.19"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-32206","cwe":"CWE-770","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32206","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32206","date":"2026-10-08","epss":0.33097,"percentile":0.98328}],"risk":16.5485,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-32206"},"relatedVulnerabilities":[{"id":"CVE-2022-32206","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-32206","cwe":"CWE-770","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32206","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32206","date":"2026-10-08","epss":0.33097,"percentile":0.98328}],"urls":["http://seclists.org/fulldisclosure/2022/Oct/28","http://seclists.org/fulldisclosure/2022/Oct/41","http://www.openwall.com/lists/oss-security/2023/02/15/3","https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf","https://hackerone.com/reports/1570651","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20220915-0003/","https://support.apple.com/kb/HT213488","https://www.debian.org/security/2022/dsa-5197"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-32206","description":"curl < 7.84.0 supports \"chained\" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable \"links\" in this \"decompression chain\" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a \"malloc bomb\", makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.19"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-32206","versionConstraint":"< 7.58.0-2ubuntu3.19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-32206","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.19"],"available":[{"date":"2022-06-27","kind":"advisory","version":"7.58.0-2ubuntu3.19"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-32206","cwe":"CWE-770","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32206","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32206","date":"2026-10-08","epss":0.33097,"percentile":0.98328}],"risk":16.5485,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-32206"},"relatedVulnerabilities":[{"id":"CVE-2022-32206","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-32206","cwe":"CWE-770","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32206","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32206","date":"2026-10-08","epss":0.33097,"percentile":0.98328}],"urls":["http://seclists.org/fulldisclosure/2022/Oct/28","http://seclists.org/fulldisclosure/2022/Oct/41","http://www.openwall.com/lists/oss-security/2023/02/15/3","https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf","https://hackerone.com/reports/1570651","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20220915-0003/","https://support.apple.com/kb/HT213488","https://www.debian.org/security/2022/dsa-5197"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-32206","description":"curl < 7.84.0 supports \"chained\" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable \"links\" in this \"decompression chain\" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a \"malloc bomb\", makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5ww9-j83m-q7qx","versionConstraint":">=2.9.0,<2.9.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5ww9-j83m-q7qx","fix":{"state":"fixed","versions":["2.9.9"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12086","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-12086","date":"2026-10-08","epss":0.21949,"percentile":0.97604}],"risk":16.46175,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-12086","https://github.com/FasterXML/jackson-databind/issues/2326","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.9","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:2998","https://access.redhat.com/errata/RHSA-2019:3044","https://access.redhat.com/errata/RHSA-2019:3045","https://access.redhat.com/errata/RHSA-2019:3046","https://access.redhat.com/errata/RHSA-2019:3050","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/88cd25375805950ae7337e669b0cb0eeda98b9604c1b8d806dccbad2@%3Creviews.spark.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5@%3Csolr-user.lucene.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/05/msg00030.html","https://seclists.org/bugtraq/2019/May/68","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://lists.apache.org/thread.html/rda99599896c3667f2cc9e9d34c7b6ef5d2bbed1f4801e1d75a2b0679@%3Ccommits.nifi.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://web.archive.org/web/20200227030031/http://www.securityfocus.com/bid/109227","https://github.com/FasterXML/jackson-databind/commit/efc3c0d02f4743dbaa6d1b9c466772a2f13d966b","https://github.com/FasterXML/jackson-databind/commit/dda513bd7251b4f32b7b60b1c13740e3b5a43024","https://github.com/FasterXML/jackson-databind/commit/d30f036208ab1c60bd5ce429cb4f7f1a3e5682e8","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC","https://security.netapp.com/advisory/ntap-20190530-0003","https://web.archive.org/web/20200808181049/http://russiansecurity.expert/2016/04/20/mysql-connect-file-read"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5ww9-j83m-q7qx","description":"Information exposure in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-12086","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12086","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-12086","date":"2026-10-08","epss":0.21949,"percentile":0.97604}],"urls":["http://russiansecurity.expert/2016/04/20/mysql-connect-file-read/","http://www.securityfocus.com/bid/109227","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:2998","https://access.redhat.com/errata/RHSA-2019:3044","https://access.redhat.com/errata/RHSA-2019:3045","https://access.redhat.com/errata/RHSA-2019:3046","https://access.redhat.com/errata/RHSA-2019:3050","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://github.com/FasterXML/jackson-databind/issues/2326","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.9","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/88cd25375805950ae7337e669b0cb0eeda98b9604c1b8d806dccbad2%40%3Creviews.spark.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rda99599896c3667f2cc9e9d34c7b6ef5d2bbed1f4801e1d75a2b0679%40%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/05/msg00030.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC/","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12086","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server reachable by the victim, an attacker can send a crafted JSON message that allows them to read arbitrary local files on the server. This occurs because of missing com.mysql.cj.jdbc.admin.MiniAdmin validation."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-2511","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-2511","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2511","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-2511","date":"2026-10-08","epss":0.52421,"percentile":0.98938}],"risk":15.726299999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2511"},"relatedVulnerabilities":[{"id":"CVE-2024-2511","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2511","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-2511","date":"2026-10-08","epss":0.52421,"percentile":0.98938}],"urls":["https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce","https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d","https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08","https://github.openssl.org/openssl/extended-releases/commit/5f8d25770ae6437db119dfc951e207271a326640","https://www.openssl.org/news/secadv/20240408.txt","http://www.openwall.com/lists/oss-security/2024/04/08/5","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20240503-0013/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-354112.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2511","description":"Issue summary: Some non-default TLS server configurations can cause unbounded\nmemory growth when processing TLSv1.3 sessions\n\nImpact summary: An attacker may exploit certain server configurations to trigger\nunbounded memory growth that would lead to a Denial of Service\n\nThis problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is\nbeing used (but not if early_data support is also configured and the default\nanti-replay protection is in use). In this case, under certain conditions, the\nsession cache can get into an incorrect state and it will fail to flush properly\nas it fills. The session cache will continue to grow in an unbounded manner. A\nmalicious client could deliberately create the scenario for this failure to\nforce a Denial of Service. It may also happen by accident in normal operation.\n\nThis issue only affects TLS servers supporting TLSv1.3. It does not affect TLS\nclients.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL\n1.0.2 is also not affected by this issue."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-2511","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-2511","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2511","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-2511","date":"2026-10-08","epss":0.52421,"percentile":0.98938}],"risk":15.726299999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2511"},"relatedVulnerabilities":[{"id":"CVE-2024-2511","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2511","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-2511","date":"2026-10-08","epss":0.52421,"percentile":0.98938}],"urls":["https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce","https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d","https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08","https://github.openssl.org/openssl/extended-releases/commit/5f8d25770ae6437db119dfc951e207271a326640","https://www.openssl.org/news/secadv/20240408.txt","http://www.openwall.com/lists/oss-security/2024/04/08/5","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20240503-0013/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-354112.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2511","description":"Issue summary: Some non-default TLS server configurations can cause unbounded\nmemory growth when processing TLSv1.3 sessions\n\nImpact summary: An attacker may exploit certain server configurations to trigger\nunbounded memory growth that would lead to a Denial of Service\n\nThis problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is\nbeing used (but not if early_data support is also configured and the default\nanti-replay protection is in use). In this case, under certain conditions, the\nsession cache can get into an incorrect state and it will fail to flush properly\nas it fills. The session cache will continue to grow in an unbounded manner. A\nmalicious client could deliberately create the scenario for this failure to\nforce a Denial of Service. It may also happen by accident in normal operation.\n\nThis issue only affects TLS servers supporting TLSv1.3. It does not affect TLS\nclients.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL\n1.0.2 is also not affected by this issue."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-23840","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-23840","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.8"],"available":[{"date":"2021-02-18","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-23840","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23840","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23840","date":"2026-10-08","epss":0.50732,"percentile":0.98897}],"risk":15.2196,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-23840"},"relatedVulnerabilities":[{"id":"CVE-2021-23840","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23840","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23840","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23840","date":"2026-10-08","epss":0.50732,"percentile":0.98897}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=6a51b9e1d0cf0bf8515f7201b68fb0a3482b3dc1","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9b1129239f3ebb1d1c98ce9ed41d5c9476c47cb2","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44846","https://kc.mcafee.com/corporate/index?page=content&id=SB10366","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/202103-03","https://security.netapp.com/advisory/ntap-20210219-0009/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-4855","https://www.openssl.org/news/secadv/20210216.txt","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-03","https://www.tenable.com/security/tns-2021-09","https://www.tenable.com/security/tns-2021-10"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23840","description":"Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x)."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-23840","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-23840","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.8"],"available":[{"date":"2021-02-18","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-23840","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23840","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23840","date":"2026-10-08","epss":0.50732,"percentile":0.98897}],"risk":15.2196,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-23840"},"relatedVulnerabilities":[{"id":"CVE-2021-23840","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23840","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23840","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23840","date":"2026-10-08","epss":0.50732,"percentile":0.98897}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=6a51b9e1d0cf0bf8515f7201b68fb0a3482b3dc1","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9b1129239f3ebb1d1c98ce9ed41d5c9476c47cb2","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44846","https://kc.mcafee.com/corporate/index?page=content&id=SB10366","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/202103-03","https://security.netapp.com/advisory/ntap-20210219-0009/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-4855","https://www.openssl.org/news/secadv/20210216.txt","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-03","https://www.tenable.com/security/tns-2021-09","https://www.tenable.com/security/tns-2021-10"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23840","description":"Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x)."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.99"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7w75-32cg-r6g2","versionConstraint":">=8.5.0,<=8.5.98 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7w75-32cg-r6g2","fix":{"state":"fixed","versions":["8.5.99"],"available":[{"date":"2024-03-16","kind":"first-observed","version":"8.5.99"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-24549","cwe":"CWE-20","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-24549","date":"2026-10-08","epss":0.23072,"percentile":0.97711}],"risk":13.90088,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-24549","https://lists.apache.org/thread/4c50rmomhbbsdgfjsgwlb51xdwfjdcvg","https://github.com/apache/tomcat/commit/0cac540a882220231ba7a82330483cbd5f6b1f96","https://github.com/apache/tomcat/commit/810f49d5ff6d64b704af85d5b8d0aab9ec3c83f5","https://github.com/apache/tomcat/commit/8e03be9f2698f2da9027d40b9e9c0c9429b74dc0","https://github.com/apache/tomcat/commit/d07c82194edb69d99b438828fe2cbfadbb207843","https://security.netapp.com/advisory/ntap-20240402-0002","https://lists.debian.org/debian-lts-announce/2024/04/msg00001.html","http://www.openwall.com/lists/oss-security/2024/03/13/3","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/736G4GPZWS2DSQO5WKXO3G6OMZKFEK55","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UWIS5MMGYDZBLJYT674ZI5AWFHDZ46B"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7w75-32cg-r6g2","description":"Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests"},"relatedVulnerabilities":[{"id":"CVE-2024-24549","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-24549","cwe":"CWE-20","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-24549","date":"2026-10-08","epss":0.23072,"percentile":0.97711}],"urls":["https://lists.apache.org/thread/4c50rmomhbbsdgfjsgwlb51xdwfjdcvg","http://www.openwall.com/lists/oss-security/2024/03/13/3","https://lists.debian.org/debian-lts-announce/2024/04/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UWIS5MMGYDZBLJYT674ZI5AWFHDZ46B/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/736G4GPZWS2DSQO5WKXO3G6OMZKFEK55/","https://security.netapp.com/advisory/ntap-20240402-0002/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-24549","description":"Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Other, older, EOL versions may also be affected.\n\nUsers are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.63"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j39c-c8hj-x4j3","versionConstraint":">=8.5.0,<8.5.63 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j39c-c8hj-x4j3","fix":{"state":"fixed","versions":["8.5.63"],"available":[{"date":"2021-06-17","kind":"first-observed","version":"8.5.63"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-25122","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2021-25122","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-25122","date":"2026-10-08","epss":0.18114,"percentile":0.97132}],"risk":13.5855,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-25122","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7@%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rcd90bf36b1877e1310b87ecd14ed7bbb15da52b297efd9f0e7253a3b@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd0463f9a5cbc02a485404c4b990f0da452e5ac5c237808edba11c947@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9@%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/03/msg00018.html","http://www.openwall.com/lists/oss-security/2021/03/01/1","https://www.debian.org/security/2021/dsa-4891","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://security.gentoo.org/glsa/202208-34","https://security.netapp.com/advisory/ntap-20210409-0002","https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd0463f9a5cbc02a485404c4b990f0da452e5ac5c237808edba11c947%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rcd90bf36b1877e1310b87ecd14ed7bbb15da52b297efd9f0e7253a3b%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cannounce.apache.org%3E"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j39c-c8hj-x4j3","description":"Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2021-25122","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-25122","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2021-25122","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-25122","date":"2026-10-08","epss":0.18114,"percentile":0.97132}],"urls":["http://www.openwall.com/lists/oss-security/2021/03/01/1","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rcd90bf36b1877e1310b87ecd14ed7bbb15da52b297efd9f0e7253a3b%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd0463f9a5cbc02a485404c4b990f0da452e5ac5c237808edba11c947%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/03/msg00018.html","https://security.gentoo.org/glsa/202208-34","https://security.netapp.com/advisory/ntap-20210409-0002/","https://www.debian.org/security/2021/dsa-4891","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-25122","description":"When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-4559","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2007-4559","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2007-4559","date":"2026-10-08","epss":0.27095,"percentile":0.98006}],"risk":13.547500000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2007-4559"},"relatedVulnerabilities":[{"id":"CVE-2007-4559","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2007-4559","date":"2026-10-08","epss":0.27095,"percentile":0.98006}],"urls":["http://mail.python.org/pipermail/python-dev/2007-August/074290.html","http://mail.python.org/pipermail/python-dev/2007-August/074292.html","http://secunia.com/advisories/26623","http://www.vupen.com/english/advisories/2007/3022","https://bugzilla.redhat.com/show_bug.cgi?id=263261","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/","https://security.gentoo.org/glsa/202309-06","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-4559","description":"Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-4559","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2007-4559","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2007-4559","date":"2026-10-08","epss":0.27095,"percentile":0.98006}],"risk":13.547500000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2007-4559"},"relatedVulnerabilities":[{"id":"CVE-2007-4559","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2007-4559","date":"2026-10-08","epss":0.27095,"percentile":0.98006}],"urls":["http://mail.python.org/pipermail/python-dev/2007-August/074290.html","http://mail.python.org/pipermail/python-dev/2007-August/074292.html","http://secunia.com/advisories/26623","http://www.vupen.com/english/advisories/2007/3022","https://bugzilla.redhat.com/show_bug.cgi?id=263261","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/","https://security.gentoo.org/glsa/202309-06","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-4559","description":"Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2007-4559","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2007-4559","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2007-4559","date":"2026-10-08","epss":0.27095,"percentile":0.98006}],"risk":13.547500000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2007-4559"},"relatedVulnerabilities":[{"id":"CVE-2007-4559","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2007-4559","date":"2026-10-08","epss":0.27095,"percentile":0.98006}],"urls":["http://mail.python.org/pipermail/python-dev/2007-August/074290.html","http://mail.python.org/pipermail/python-dev/2007-August/074292.html","http://secunia.com/advisories/26623","http://www.vupen.com/english/advisories/2007/3022","https://bugzilla.redhat.com/show_bug.cgi?id=263261","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/","https://security.gentoo.org/glsa/202309-06","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-4559","description":"Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-4559","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2007-4559","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2007-4559","date":"2026-10-08","epss":0.27095,"percentile":0.98006}],"risk":13.547500000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2007-4559"},"relatedVulnerabilities":[{"id":"CVE-2007-4559","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2007-4559","date":"2026-10-08","epss":0.27095,"percentile":0.98006}],"urls":["http://mail.python.org/pipermail/python-dev/2007-August/074290.html","http://mail.python.org/pipermail/python-dev/2007-August/074292.html","http://secunia.com/advisories/26623","http://www.vupen.com/english/advisories/2007/3022","https://bugzilla.redhat.com/show_bug.cgi?id=263261","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/","https://security.gentoo.org/glsa/202309-06","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-4559","description":"Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9gph-22xh-8x98","versionConstraint":">=2.7.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-9gph-22xh-8x98","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36179","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36179","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36179","date":"2026-10-08","epss":0.17065,"percentile":0.97009}],"risk":13.3107,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36179","https://github.com/FasterXML/jackson-databind/issues/3004","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.apache.org/thread.html/rc255f41d9a61d3dc79a51fb5c713de4ae10e71e3673feeb0b180b436@%3Cissues.spark.apache.org%3E","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3ded28aece694d0df39c9f0fa1ff385b14a8656b"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9gph-22xh-8x98","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36179","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36179","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36179","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36179","date":"2026-10-08","epss":0.17065,"percentile":0.97009}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/3004","https://lists.apache.org/thread.html/rc255f41d9a61d3dc79a51fb5c713de4ae10e71e3673feeb0b180b436%40%3Cissues.spark.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36179","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS."}]},{"artifact":{"id":"a5ac54476e47c1ea","cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.35-2ubuntu2.1:*:*:*:*:*:*:*"],"name":"libnss3","purl":"pkg:deb/ubuntu/libnss3@2%3A3.35-2ubuntu2.1?arch=amd64&distro=ubuntu-18.04&upstream=nss","type":"deb","version":"2:3.35-2ubuntu2.1","language":"","licenses":["HPND","HPND-sell-variant","MIT","MPL-2.0","Zlib","blessing"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss3/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libnss3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nss"}]},"matchDetails":[{"fix":{"suggestedVersion":"2:3.35-2ubuntu2.13"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-43527","versionConstraint":"< 2:3.35-2ubuntu2.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nss","version":"2:3.35-2ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-43527","fix":{"state":"fixed","versions":["2:3.35-2ubuntu2.13"],"available":[{"date":"2021-12-01","kind":"advisory","version":"2:3.35-2ubuntu2.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-43527","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-43527","date":"2026-10-08","epss":0.17563,"percentile":0.97071}],"risk":13.172250000000002,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-43527"},"relatedVulnerabilities":[{"id":"CVE-2021-43527","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-43527","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-43527","date":"2026-10-08","epss":0.17563,"percentile":0.97071}],"urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=1737470","https://cert-portal.siemens.com/productcert/pdf/ssa-594438.pdf","https://ftp.mozilla.org/pub/security/nss/releases/NSS_3_68_1_RTM/","https://ftp.mozilla.org/pub/security/nss/releases/NSS_3_73_RTM/","https://security.gentoo.org/glsa/202212-05","https://security.netapp.com/advisory/ntap-20211229-0002/","https://www.mozilla.org/security/advisories/mfsa2021-51/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.starwindsoftware.com/security/sw-20220802-0001/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-43527","description":"NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \\#7, or PKCS \\#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-288c-cq4h-88gq","versionConstraint":">=2.7.0.0,<=2.9.10.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-288c-cq4h-88gq","fix":{"state":"fixed","versions":["2.9.10.7"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25649","cwe":"CWE-611","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-25649","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-25649","date":"2026-10-08","epss":0.1726,"percentile":0.97035}],"risk":12.945,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-25649","https://github.com/FasterXML/jackson-databind/issues/2589","https://bugzilla.redhat.com/show_bug.cgi?id=1887664","https://lists.apache.org/thread.html/r04529cedaca40c2ff90af4880493f9c88a8ebf4d1d6c861d23108a5a@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r0b8dc3acd4503e4ecb6fbd6ea7d95f59941168d8452ac0ab1d1d96bb@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r1b7ed0c4b6c4301d4dfd6fdbc5581b0a789d3240cab55d766f33c6c6@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r2882fc1f3032cd7be66e28787f04ec6f1874ac68d47e310e30ff7eb1@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r2b6ddb3a4f4cd11d8f6305011e1b7438ba813511f2e3ab3180c7ffda@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r31f4ee7d561d56a0c2c2c6eb1d6ce3e05917ff9654fdbfec05dc2b83@%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/r3e6ae311842de4e64c5d560a475b7f9cc7e0a9a8649363c6cf7537eb@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r45e7350dfc92bb192f3f88e9971c11ab2be0953cc375be3dda5170bd@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r5f8a1608d758936bd6bbc5eed980777437b611537bf6fff40663fc71@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r63c87aab97155f3f3cbe11d030c4a184ea0de440ee714977db02e956@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r68d029ee74ab0f3b0569d0c05f5688cb45dd3abe96a6534735252805@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r6b11eca1d646f45eb0d35d174e6b1e47cfae5295b92000856bfb6304@%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r6b11eca1d646f45eb0d35d174e6b1e47cfae5295b92000856bfb6304@%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r6e3d4f7991542119a4ca6330271d7fbf7b9fb3abab24ada82ddf1ee4@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r78d53a0a269c18394daf5940105dc8c7f9a2399503c2e78be20abe7e@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r86c78bf7656fdb2dab69cbf17f3d7492300f771025f1a3a65d5e5ce5@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r8937a7160717fe8b2221767163c4de4f65bc5466405cb1c5310f9080@%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r8937a7160717fe8b2221767163c4de4f65bc5466405cb1c5310f9080@%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r900d4408c4189b376d1ec580ea7740ea6f8710dc2f0b7e9c9eeb5ae0@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r90d1e97b0a743cf697d89a792a9b669909cc5a1692d1e0083a22e66c@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r91722ecfba688b0c565675f8bf380269fde8ec62b54d6161db544c22@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r94c7e86e546120f157264ba5ba61fd29b3a8d530ed325a9b4fa334d7@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r95a297eb5fd1f2d3a2281f15340e2413f952e9d5503296c3adc7201a@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r98bfe3b90ea9408f12c4b447edcb5638703d80bc782430aa0c210a54@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra1157e57a01d25e36b0dc17959ace758fc21ba36746de29ba1d8b130@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/ra95faf968f3463acb3f31a6fbec31453fc5045325f99f396961886d3@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/raf13235de6df1d47a717199e1ecd700dff3236632f5c9a1488d9845b@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rb674520b9f6c808c1bf263b1369e14048ec3243615f35cfd24e33604@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc15e90bbef196a5c6c01659e015249d6c9a73581ca9afb8aeecf00d2@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rc88f2fa2b7bd6443921727aeee7704a1fb02433e722e2abf677e0d3d@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc959cdb57c4fe198316130ff4a5ecbf9d680e356032ff2e9f4f05d54@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rd317f15a675d114dbf5b488d27eeb2467b4424356b16116eb18a652d@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rd6f6bf848c2d47fa4a85c27d011d948778b8f7e58ba495968435a0b3@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdf9a34726482222c90d50ae1b9847881de67dde8cfde4999633d2cdc@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re16f81d3ad49a93dd2f0cba9f8fc88e5fb89f30bf9a2ad7b6f3e69c1@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/re96dc7a13e13e56190a5d80f9e5440a0d0c83aeec6467b562fbf2dca@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rf1809a1374041a969d77afab21fc38925de066bc97e86157d3ac3402@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r0881e23bd9034c8f51fdccdc8f4d085ba985dcd738f8520569ca5c3d@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r2eb66c182853c69ecfb52f63d3dec09495e9b65be829fd889a081ae1@%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/r5b130fe668503c4b7e2caf1b16f86b7f2070fd1b7ef8f26195a2ffbd@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rd57c7582adc90e233f23f3727db3df9115b27a823b92374f11453f34@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r011d1430e8f40dff9550c3bc5d0f48b14c01ba8aecabd91d5e495386@%3Ccommits.turbine.apache.org%3E","https://lists.apache.org/thread.html/r2f5c5479f99398ef344b7ebd4d90bc3316236c45d0f3bc42090efcd7@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r407538adec3185dd35a05c9a26ae2f74425b15132470cf540f41d85b@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r605764e05e201db33b3e9c2e66ff620658f07ad74f296abe483f7042@%3Creviews.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r765283e145049df9b8998f14dcd444345555aae02b1610cfb3188bf8@%3Cnotifications.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r7cb5b4b3e4bd41a8042e5725b7285877a17bcbf07f4eb3f7b316af60@%3Creviews.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r6cbd599b80e787f02ff7a1391d9278a03f37d6a6f4f943f0f01a62fb@%3Creviews.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r73bef1bb601a9f093f915f8075eb49fcca51efade57b817afd5def07@%3Ccommits.iotdb.apache.org%3E","https://lists.apache.org/thread.html/ra409f798a1e5a6652b7097429b388650ccd65fd958cee0b6f69bba00@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rdca8711bb7aa5d47a44682606cd0ea3497e2e922f22b7ee83e81e6c1@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r8ae961c80930e2717c75025414ce48a432cea1137c02f648b1fb9524@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r6a4f3ef6edfed2e0884269d84798f766779bbbc1005f7884e0800d61@%3Cdev.knox.apache.org%3E","https://lists.apache.org/thread.html/rc82ff47853289e9cd17f5cfbb053c04cafc75ee32e3d7223963f83bb@%3Cdev.knox.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://lists.apache.org/thread.html/r8764bb835bcb8e311c882ff91dd3949c9824e905e880930be56f6ba3@%3Cuser.spark.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cusers.kafka.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r024b7bda9c43c5560d81238748775c5ecfe01b57280f90df1f773949@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r6a6df5647583541e3cb71c75141008802f7025cee1c430d4ed78f4cc@%3Cissues.hive.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3d932709abd0b5390efe67451653fc9efa9db677","https://github.com/FasterXML/jackson-databind/commit/612f971b78c60202e9cd75a299050c8f2d724a59","https://security.netapp.com/advisory/ntap-20210108-0007","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6X2UT4X6M7DLQYBOOHMXBWGYJ65RL2CT"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-288c-cq4h-88gq","description":"XML External Entity (XXE) Injection in Jackson Databind"},"relatedVulnerabilities":[{"id":"CVE-2020-25649","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25649","cwe":"CWE-611","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-25649","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-25649","date":"2026-10-08","epss":0.1726,"percentile":0.97035}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1887664","https://github.com/FasterXML/jackson-databind/issues/2589","https://lists.apache.org/thread.html/r011d1430e8f40dff9550c3bc5d0f48b14c01ba8aecabd91d5e495386%40%3Ccommits.turbine.apache.org%3E","https://lists.apache.org/thread.html/r024b7bda9c43c5560d81238748775c5ecfe01b57280f90df1f773949%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r04529cedaca40c2ff90af4880493f9c88a8ebf4d1d6c861d23108a5a%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r0881e23bd9034c8f51fdccdc8f4d085ba985dcd738f8520569ca5c3d%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r0b8dc3acd4503e4ecb6fbd6ea7d95f59941168d8452ac0ab1d1d96bb%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r1b7ed0c4b6c4301d4dfd6fdbc5581b0a789d3240cab55d766f33c6c6%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r2882fc1f3032cd7be66e28787f04ec6f1874ac68d47e310e30ff7eb1%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r2b6ddb3a4f4cd11d8f6305011e1b7438ba813511f2e3ab3180c7ffda%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r2eb66c182853c69ecfb52f63d3dec09495e9b65be829fd889a081ae1%40%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/r2f5c5479f99398ef344b7ebd4d90bc3316236c45d0f3bc42090efcd7%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r31f4ee7d561d56a0c2c2c6eb1d6ce3e05917ff9654fdbfec05dc2b83%40%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/r3e6ae311842de4e64c5d560a475b7f9cc7e0a9a8649363c6cf7537eb%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r407538adec3185dd35a05c9a26ae2f74425b15132470cf540f41d85b%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r45e7350dfc92bb192f3f88e9971c11ab2be0953cc375be3dda5170bd%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r5b130fe668503c4b7e2caf1b16f86b7f2070fd1b7ef8f26195a2ffbd%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r5f8a1608d758936bd6bbc5eed980777437b611537bf6fff40663fc71%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r605764e05e201db33b3e9c2e66ff620658f07ad74f296abe483f7042%40%3Creviews.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r63c87aab97155f3f3cbe11d030c4a184ea0de440ee714977db02e956%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r68d029ee74ab0f3b0569d0c05f5688cb45dd3abe96a6534735252805%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r6a4f3ef6edfed2e0884269d84798f766779bbbc1005f7884e0800d61%40%3Cdev.knox.apache.org%3E","https://lists.apache.org/thread.html/r6a6df5647583541e3cb71c75141008802f7025cee1c430d4ed78f4cc%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r6b11eca1d646f45eb0d35d174e6b1e47cfae5295b92000856bfb6304%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r6b11eca1d646f45eb0d35d174e6b1e47cfae5295b92000856bfb6304%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r6cbd599b80e787f02ff7a1391d9278a03f37d6a6f4f943f0f01a62fb%40%3Creviews.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r6e3d4f7991542119a4ca6330271d7fbf7b9fb3abab24ada82ddf1ee4%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r73bef1bb601a9f093f915f8075eb49fcca51efade57b817afd5def07%40%3Ccommits.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r765283e145049df9b8998f14dcd444345555aae02b1610cfb3188bf8%40%3Cnotifications.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r78d53a0a269c18394daf5940105dc8c7f9a2399503c2e78be20abe7e%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r7cb5b4b3e4bd41a8042e5725b7285877a17bcbf07f4eb3f7b316af60%40%3Creviews.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r86c78bf7656fdb2dab69cbf17f3d7492300f771025f1a3a65d5e5ce5%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r8764bb835bcb8e311c882ff91dd3949c9824e905e880930be56f6ba3%40%3Cuser.spark.apache.org%3E","https://lists.apache.org/thread.html/r8937a7160717fe8b2221767163c4de4f65bc5466405cb1c5310f9080%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r8937a7160717fe8b2221767163c4de4f65bc5466405cb1c5310f9080%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r8ae961c80930e2717c75025414ce48a432cea1137c02f648b1fb9524%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r900d4408c4189b376d1ec580ea7740ea6f8710dc2f0b7e9c9eeb5ae0%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r90d1e97b0a743cf697d89a792a9b669909cc5a1692d1e0083a22e66c%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r91722ecfba688b0c565675f8bf380269fde8ec62b54d6161db544c22%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r94c7e86e546120f157264ba5ba61fd29b3a8d530ed325a9b4fa334d7%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r95a297eb5fd1f2d3a2281f15340e2413f952e9d5503296c3adc7201a%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r98bfe3b90ea9408f12c4b447edcb5638703d80bc782430aa0c210a54%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra1157e57a01d25e36b0dc17959ace758fc21ba36746de29ba1d8b130%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/ra409f798a1e5a6652b7097429b388650ccd65fd958cee0b6f69bba00%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/ra95faf968f3463acb3f31a6fbec31453fc5045325f99f396961886d3%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/raf13235de6df1d47a717199e1ecd700dff3236632f5c9a1488d9845b%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rb674520b9f6c808c1bf263b1369e14048ec3243615f35cfd24e33604%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/rc15e90bbef196a5c6c01659e015249d6c9a73581ca9afb8aeecf00d2%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rc82ff47853289e9cd17f5cfbb053c04cafc75ee32e3d7223963f83bb%40%3Cdev.knox.apache.org%3E","https://lists.apache.org/thread.html/rc88f2fa2b7bd6443921727aeee7704a1fb02433e722e2abf677e0d3d%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc959cdb57c4fe198316130ff4a5ecbf9d680e356032ff2e9f4f05d54%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rd317f15a675d114dbf5b488d27eeb2467b4424356b16116eb18a652d%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rd57c7582adc90e233f23f3727db3df9115b27a823b92374f11453f34%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rd6f6bf848c2d47fa4a85c27d011d948778b8f7e58ba495968435a0b3%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdca8711bb7aa5d47a44682606cd0ea3497e2e922f22b7ee83e81e6c1%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rdf9a34726482222c90d50ae1b9847881de67dde8cfde4999633d2cdc%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re16f81d3ad49a93dd2f0cba9f8fc88e5fb89f30bf9a2ad7b6f3e69c1%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/re96dc7a13e13e56190a5d80f9e5440a0d0c83aeec6467b562fbf2dca%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rf1809a1374041a969d77afab21fc38925de066bc97e86157d3ac3402%40%3Ccommits.karaf.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6X2UT4X6M7DLQYBOOHMXBWGYJ65RL2CT/","https://security.netapp.com/advisory/ntap-20210108-0007/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-25649","description":"A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.60"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2rvv-w9r2-rg7m","versionConstraint":">=8.5.0,<8.5.60 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-2rvv-w9r2-rg7m","fix":{"state":"fixed","versions":["8.5.60"],"available":[{"date":"2021-05-14","kind":"first-observed","version":"8.5.60"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-24122","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2021-24122","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-24122","date":"2026-10-08","epss":0.22852,"percentile":0.9769}],"risk":12.454340000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-24122","https://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52@%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7382e1e35b9bc7c8f320b90ad77e74c13172d08034e20c18000fe710@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r776c64337495bf28b7d5597268114a888e3fad6045c40a0da0c66d4d@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r7e0bb9ea415724550e2b325e143b23e269579e54d66fcd7754bd0c20@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb32a73b7cb919d4f44a2596b6b951274c0004fc8b0e393d6829a45f9@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rca833c6d42b7b9ce1563488c0929f29fcc95947d86e5e740258c8937@%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/03/msg00018.html","http://www.openwall.com/lists/oss-security/2021/01/14/1","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/apache/tomcat/commit/7f004ac4531c45f9a2a2d1470561fe135cf27bc2","https://github.com/apache/tomcat/commit/800b03140e640f8892f27021e681645e8e320177","https://github.com/apache/tomcat/commit/920dddbdb981f92e8d5872a4bb126a10af5ca8a9","https://github.com/apache/tomcat/commit/935fc5582dc25ae10bab6f9d5629ff8d996cb533","https://tomcat.apache.org/security-9.html","https://tomcat.apache.org/security-8.html","https://tomcat.apache.org/security-7.html","https://tomcat.apache.org/security-10.html","https://security.netapp.com/advisory/ntap-20210212-0008"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2rvv-w9r2-rg7m","description":"Information Disclosure in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2021-24122","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-24122","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2021-24122","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-24122","date":"2026-10-08","epss":0.22852,"percentile":0.9769}],"urls":["http://www.openwall.com/lists/oss-security/2021/01/14/1","https://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7382e1e35b9bc7c8f320b90ad77e74c13172d08034e20c18000fe710%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r776c64337495bf28b7d5597268114a888e3fad6045c40a0da0c66d4d%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r7e0bb9ea415724550e2b325e143b23e269579e54d66fcd7754bd0c20%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb32a73b7cb919d4f44a2596b6b951274c0004fc8b0e393d6829a45f9%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rca833c6d42b7b9ce1563488c0929f29fcc95947d86e5e740258c8937%40%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/03/msg00018.html","https://security.netapp.com/advisory/ntap-20210212-0008/","https://www.oracle.com//security-alerts/cpujul2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-24122","description":"When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was caused by the inconsistent behaviour of the Windows API (FindFirstFileW) in some circumstances."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-23336","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-23336","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23336","date":"2026-10-08","epss":0.40736,"percentile":0.98622}],"risk":12.2208,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-23336"},"relatedVulnerabilities":[{"id":"CVE-2021-23336","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:P","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23336","date":"2026-10-08","epss":0.40736,"percentile":0.98622}],"urls":["http://www.openwall.com/lists/oss-security/2021/02/19/4","http://www.openwall.com/lists/oss-security/2021/05/01/2","https://github.com/python/cpython/pull/24297","https://lists.apache.org/thread.html/ra8ce70088ba291f358e077cafdb14d174b7a1ce9a9d86d1b332d6367%40%3Cusers.airflow.apache.org%3E","https://lists.apache.org/thread.html/rc005f4de9d9b0ba943ceb8ff5a21a5c6ff8a9df52632476698d99432%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00030.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00015.html","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3EPYWWFDV22CJ5AOH5VCE72DOASZZ255/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YKKDLXL3UEZ3J426C2XTBS63AHE46SM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46N6A52EGSXHJYCZWVMBJJIH4NWIV2B5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZTM7KLHFCE3LWSEVO2NAFLUHMGYMCRY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IHQDU7NXA7EWAE4W7VO6MURVJIULEPPR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJXCMHLY7H3FIYLE4OKDYUILU2CCRUCZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LVNH6Z24IG3E67ZCQGGJ46FZB4XFLQNZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MNUN5SOMFL2BBKP6ZAICIIUPQKZDMGYO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6VXJZSZ6N64AILJX4CTMACYGQGHHD5C/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJSCSN722JO2E2AGPWD4NTGVELVRPB4R/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OAGSWNGZJ6HQ5ISA67SNMK3CJRKICET7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TFTELUMWZE3KV3JB2H5EE6VFRZFRD5MV/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W2LSKBEFI5SYEY5FM6ICZVZM5WRQUCS4/","https://security.gentoo.org/glsa/202104-04","https://security.netapp.com/advisory/ntap-20210326-0004/","https://snyk.io/blog/cache-poisoning-in-popular-open-source-packages/","https://snyk.io/vuln/SNYK-UPSTREAM-PYTHONCPYTHON-1074933","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23336","description":"The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-23336","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-23336","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23336","date":"2026-10-08","epss":0.40736,"percentile":0.98622}],"risk":12.2208,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-23336"},"relatedVulnerabilities":[{"id":"CVE-2021-23336","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:P","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23336","date":"2026-10-08","epss":0.40736,"percentile":0.98622}],"urls":["http://www.openwall.com/lists/oss-security/2021/02/19/4","http://www.openwall.com/lists/oss-security/2021/05/01/2","https://github.com/python/cpython/pull/24297","https://lists.apache.org/thread.html/ra8ce70088ba291f358e077cafdb14d174b7a1ce9a9d86d1b332d6367%40%3Cusers.airflow.apache.org%3E","https://lists.apache.org/thread.html/rc005f4de9d9b0ba943ceb8ff5a21a5c6ff8a9df52632476698d99432%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00030.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00015.html","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3EPYWWFDV22CJ5AOH5VCE72DOASZZ255/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YKKDLXL3UEZ3J426C2XTBS63AHE46SM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46N6A52EGSXHJYCZWVMBJJIH4NWIV2B5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZTM7KLHFCE3LWSEVO2NAFLUHMGYMCRY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IHQDU7NXA7EWAE4W7VO6MURVJIULEPPR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJXCMHLY7H3FIYLE4OKDYUILU2CCRUCZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LVNH6Z24IG3E67ZCQGGJ46FZB4XFLQNZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MNUN5SOMFL2BBKP6ZAICIIUPQKZDMGYO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6VXJZSZ6N64AILJX4CTMACYGQGHHD5C/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJSCSN722JO2E2AGPWD4NTGVELVRPB4R/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OAGSWNGZJ6HQ5ISA67SNMK3CJRKICET7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TFTELUMWZE3KV3JB2H5EE6VFRZFRD5MV/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W2LSKBEFI5SYEY5FM6ICZVZM5WRQUCS4/","https://security.gentoo.org/glsa/202104-04","https://security.netapp.com/advisory/ntap-20210326-0004/","https://snyk.io/blog/cache-poisoning-in-popular-open-source-packages/","https://snyk.io/vuln/SNYK-UPSTREAM-PYTHONCPYTHON-1074933","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23336","description":"The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-23336","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-23336","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23336","date":"2026-10-08","epss":0.40736,"percentile":0.98622}],"risk":12.2208,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-23336"},"relatedVulnerabilities":[{"id":"CVE-2021-23336","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:P","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23336","date":"2026-10-08","epss":0.40736,"percentile":0.98622}],"urls":["http://www.openwall.com/lists/oss-security/2021/02/19/4","http://www.openwall.com/lists/oss-security/2021/05/01/2","https://github.com/python/cpython/pull/24297","https://lists.apache.org/thread.html/ra8ce70088ba291f358e077cafdb14d174b7a1ce9a9d86d1b332d6367%40%3Cusers.airflow.apache.org%3E","https://lists.apache.org/thread.html/rc005f4de9d9b0ba943ceb8ff5a21a5c6ff8a9df52632476698d99432%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00030.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00015.html","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3EPYWWFDV22CJ5AOH5VCE72DOASZZ255/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YKKDLXL3UEZ3J426C2XTBS63AHE46SM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46N6A52EGSXHJYCZWVMBJJIH4NWIV2B5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZTM7KLHFCE3LWSEVO2NAFLUHMGYMCRY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IHQDU7NXA7EWAE4W7VO6MURVJIULEPPR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJXCMHLY7H3FIYLE4OKDYUILU2CCRUCZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LVNH6Z24IG3E67ZCQGGJ46FZB4XFLQNZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MNUN5SOMFL2BBKP6ZAICIIUPQKZDMGYO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6VXJZSZ6N64AILJX4CTMACYGQGHHD5C/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJSCSN722JO2E2AGPWD4NTGVELVRPB4R/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OAGSWNGZJ6HQ5ISA67SNMK3CJRKICET7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TFTELUMWZE3KV3JB2H5EE6VFRZFRD5MV/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W2LSKBEFI5SYEY5FM6ICZVZM5WRQUCS4/","https://security.gentoo.org/glsa/202104-04","https://security.netapp.com/advisory/ntap-20210326-0004/","https://snyk.io/blog/cache-poisoning-in-popular-open-source-packages/","https://snyk.io/vuln/SNYK-UPSTREAM-PYTHONCPYTHON-1074933","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23336","description":"The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-23336","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-23336","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23336","date":"2026-10-08","epss":0.40736,"percentile":0.98622}],"risk":12.2208,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-23336"},"relatedVulnerabilities":[{"id":"CVE-2021-23336","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:P","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23336","date":"2026-10-08","epss":0.40736,"percentile":0.98622}],"urls":["http://www.openwall.com/lists/oss-security/2021/02/19/4","http://www.openwall.com/lists/oss-security/2021/05/01/2","https://github.com/python/cpython/pull/24297","https://lists.apache.org/thread.html/ra8ce70088ba291f358e077cafdb14d174b7a1ce9a9d86d1b332d6367%40%3Cusers.airflow.apache.org%3E","https://lists.apache.org/thread.html/rc005f4de9d9b0ba943ceb8ff5a21a5c6ff8a9df52632476698d99432%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00030.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00015.html","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3EPYWWFDV22CJ5AOH5VCE72DOASZZ255/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YKKDLXL3UEZ3J426C2XTBS63AHE46SM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46N6A52EGSXHJYCZWVMBJJIH4NWIV2B5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZTM7KLHFCE3LWSEVO2NAFLUHMGYMCRY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IHQDU7NXA7EWAE4W7VO6MURVJIULEPPR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJXCMHLY7H3FIYLE4OKDYUILU2CCRUCZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LVNH6Z24IG3E67ZCQGGJ46FZB4XFLQNZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MNUN5SOMFL2BBKP6ZAICIIUPQKZDMGYO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6VXJZSZ6N64AILJX4CTMACYGQGHHD5C/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJSCSN722JO2E2AGPWD4NTGVELVRPB4R/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OAGSWNGZJ6HQ5ISA67SNMK3CJRKICET7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TFTELUMWZE3KV3JB2H5EE6VFRZFRD5MV/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W2LSKBEFI5SYEY5FM6ICZVZM5WRQUCS4/","https://security.gentoo.org/glsa/202104-04","https://security.netapp.com/advisory/ntap-20210326-0004/","https://snyk.io/blog/cache-poisoning-in-popular-open-source-packages/","https://snyk.io/vuln/SNYK-UPSTREAM-PYTHONCPYTHON-1074933","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23336","description":"The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-645p-88qh-w398","versionConstraint":">=2.9.0,<2.9.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-645p-88qh-w398","fix":{"state":"fixed","versions":["2.9.7"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-14718","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-14718","date":"2026-10-08","epss":0.12679,"percentile":0.96167}],"risk":11.918260000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-14718","https://github.com/FasterXML/jackson-databind/issues/2097","https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/6a78f88716c3c57aa74ec05764a37ab3874769a347805903b393b286@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/82b01bfb6787097427ce97cec6a7127e93718bc05d1efd5eaffc228f@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/ba973114605d936be276ee6ce09dfbdbf78aa56f6cdc6e79bfa7b8df@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r1d4a247329a8478073163567bbc8c8cb6b49c6bfc2bf58153a857af1@%3Ccommits.druid.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","http://www.securityfocus.com/bid/106601"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-645p-88qh-w398","description":"Arbitrary Code Execution in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2018-14718","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-14718","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-14718","date":"2026-10-08","epss":0.12679,"percentile":0.96167}],"urls":["http://www.securityfocus.com/bid/106601","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44","https://github.com/FasterXML/jackson-databind/issues/2097","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/6a78f88716c3c57aa74ec05764a37ab3874769a347805903b393b286%40%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/82b01bfb6787097427ce97cec6a7127e93718bc05d1efd5eaffc228f%40%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/ba973114605d936be276ee6ce09dfbdbf78aa56f6cdc6e79bfa7b8df%40%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r1d4a247329a8478073163567bbc8c8cb6b49c6bfc2bf58153a857af1%40%3Ccommits.druid.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-14718","description":"FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3177","versionConstraint":"< 2.7.17-1~18.04ubuntu1.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3177","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.6"],"available":[{"date":"2021-03-03","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3177","date":"2026-10-08","epss":0.23293,"percentile":0.97729}],"risk":11.6465,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3177"},"relatedVulnerabilities":[{"id":"CVE-2021-3177","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3177","date":"2026-10-08","epss":0.23293,"percentile":0.97729}],"urls":["https://bugs.python.org/issue42938","https://github.com/python/cpython/pull/24239","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html","https://lists.debian.org/debian-lts-announce/2022/02/msg00013.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO/","https://news.ycombinator.com/item?id=26185005","https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html","https://security.gentoo.org/glsa/202101-18","https://security.netapp.com/advisory/ntap-20210226-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3177","description":"Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3177","versionConstraint":"< 2.7.17-1~18.04ubuntu1.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3177","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.6"],"available":[{"date":"2021-03-03","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3177","date":"2026-10-08","epss":0.23293,"percentile":0.97729}],"risk":11.6465,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3177"},"relatedVulnerabilities":[{"id":"CVE-2021-3177","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3177","date":"2026-10-08","epss":0.23293,"percentile":0.97729}],"urls":["https://bugs.python.org/issue42938","https://github.com/python/cpython/pull/24239","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html","https://lists.debian.org/debian-lts-announce/2022/02/msg00013.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO/","https://news.ycombinator.com/item?id=26185005","https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html","https://security.gentoo.org/glsa/202101-18","https://security.netapp.com/advisory/ntap-20210226-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3177","description":"Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-3177","versionConstraint":"< 2.7.17-1~18.04ubuntu1.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3177","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.6"],"available":[{"date":"2021-03-03","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3177","date":"2026-10-08","epss":0.23293,"percentile":0.97729}],"risk":11.6465,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3177"},"relatedVulnerabilities":[{"id":"CVE-2021-3177","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3177","date":"2026-10-08","epss":0.23293,"percentile":0.97729}],"urls":["https://bugs.python.org/issue42938","https://github.com/python/cpython/pull/24239","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html","https://lists.debian.org/debian-lts-announce/2022/02/msg00013.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO/","https://news.ycombinator.com/item?id=26185005","https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html","https://security.gentoo.org/glsa/202101-18","https://security.netapp.com/advisory/ntap-20210226-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3177","description":"Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3177","versionConstraint":"< 2.7.17-1~18.04ubuntu1.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3177","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.6"],"available":[{"date":"2021-03-03","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3177","date":"2026-10-08","epss":0.23293,"percentile":0.97729}],"risk":11.6465,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3177"},"relatedVulnerabilities":[{"id":"CVE-2021-3177","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3177","date":"2026-10-08","epss":0.23293,"percentile":0.97729}],"urls":["https://bugs.python.org/issue42938","https://github.com/python/cpython/pull/24239","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html","https://lists.debian.org/debian-lts-announce/2022/02/msg00013.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO/","https://news.ycombinator.com/item?id=26185005","https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html","https://security.gentoo.org/glsa/202101-18","https://security.netapp.com/advisory/ntap-20210226-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3177","description":"Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely."}]},{"artifact":{"id":"117b6ba6e73cadab","cpes":["cpe:2.3:a:org.springframework.security:spring-security-core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:spring_security_core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:spring_security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-core:spring-security-core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-core:spring_security_core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_core:spring-security-core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_core:spring_security_core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-core:spring_security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring-security-core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring_security_core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring-security-core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring_security_core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_core:spring_security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-security-core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_security_core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring_security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring_security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring-security-core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring_security_core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-core:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_core:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-security-core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_security_core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring-security-core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security_core:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring_security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:security:5.0.7.RELEASE:*:*:*:*:*:*:*"],"name":"spring-security-core","purl":"pkg:maven/org.springframework.security/spring-security-core@5.0.7.RELEASE","type":"java-archive","version":"5.0.7.RELEASE","language":"java","licenses":[],"metadata":{"pomGroupID":"org.springframework.security","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-security-core-5.0.7.RELEASE.jar","manifestName":"","pomArtifactID":"spring-security-core","archiveDigests":[{"value":"40a0c57af6b4c3f8c611216d2579c6ab19672694","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-security-core-5.0.7.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.4.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hh32-7344-cg2f","versionConstraint":"<5.4.11 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework.security:spring-security-core","version":"5.0.7.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hh32-7344-cg2f","fix":{"state":"fixed","versions":["5.4.11"],"available":[{"date":"2024-07-06","kind":"first-observed","version":"5.4.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22978","cwe":"CWE-863","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22978","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22978","date":"2026-10-08","epss":0.12351,"percentile":0.96102}],"risk":11.60994,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22978","https://tanzu.vmware.com/security/cve-2022-22978","https://www.oracle.com/security-alerts/cpujul2022.html","https://spring.io/security/cve-2022-22978","https://security.netapp.com/advisory/ntap-20220707-0003","https://github.com/anchore/grype/issues/2158","https://github.com/spring-projects/spring-security/blob/main/web/src/main/java/org/springframework/security/web/util/matcher/RegexRequestMatcher.java"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hh32-7344-cg2f","description":"Authorization bypass in Spring Security"},"relatedVulnerabilities":[{"id":"CVE-2022-22978","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22978","cwe":"CWE-863","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22978","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22978","date":"2026-10-08","epss":0.12351,"percentile":0.96102}],"urls":["https://spring.io/security/cve-2022-22978"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22978","description":"In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass."}]},{"artifact":{"id":"f93d61afc5c3c559","cpes":["cpe:2.3:a:org.springframework.security:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:security:5.0.7.RELEASE:*:*:*:*:*:*:*"],"name":"spring-security-web","purl":"pkg:maven/org.springframework.security/spring-security-web@5.0.7.RELEASE","type":"java-archive","version":"5.0.7.RELEASE","language":"java","licenses":[],"metadata":{"pomGroupID":"org.springframework.security","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-security-web-5.0.7.RELEASE.jar","manifestName":"","pomArtifactID":"spring-security-web","archiveDigests":[{"value":"0bab3ed579d4550bb5cc40b0a7fddd0106db7c66","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-security-web-5.0.7.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.4.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hh32-7344-cg2f","versionConstraint":"<5.4.11 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework.security:spring-security-web","version":"5.0.7.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hh32-7344-cg2f","fix":{"state":"fixed","versions":["5.4.11"],"available":[{"date":"2024-10-05","kind":"first-observed","version":"5.4.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22978","cwe":"CWE-863","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22978","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22978","date":"2026-10-08","epss":0.12351,"percentile":0.96102}],"risk":11.60994,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22978","https://tanzu.vmware.com/security/cve-2022-22978","https://www.oracle.com/security-alerts/cpujul2022.html","https://spring.io/security/cve-2022-22978","https://security.netapp.com/advisory/ntap-20220707-0003","https://github.com/anchore/grype/issues/2158","https://github.com/spring-projects/spring-security/blob/main/web/src/main/java/org/springframework/security/web/util/matcher/RegexRequestMatcher.java"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hh32-7344-cg2f","description":"Authorization bypass in Spring Security"},"relatedVulnerabilities":[{"id":"CVE-2022-22978","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22978","cwe":"CWE-863","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22978","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22978","date":"2026-10-08","epss":0.12351,"percentile":0.96102}],"urls":["https://spring.io/security/cve-2022-22978"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22978","description":"In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass."}]},{"artifact":{"id":"0b1c74783f88c915","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.22.0-1ubuntu0.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-35737","versionConstraint":"< 3.22.0-1ubuntu0.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-35737","fix":{"state":"fixed","versions":["3.22.0-1ubuntu0.7"],"available":[{"date":"2022-11-07","kind":"advisory","version":"3.22.0-1ubuntu0.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-35737","cwe":"CWE-129","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-35737","date":"2026-10-08","epss":0.22774,"percentile":0.97683}],"risk":11.387,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-35737"},"relatedVulnerabilities":[{"id":"CVE-2022-35737","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-35737","cwe":"CWE-129","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-35737","date":"2026-10-08","epss":0.22774,"percentile":0.97683}],"urls":["https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/","https://kb.cert.org/vuls/id/720344","https://security.gentoo.org/glsa/202210-40","https://security.netapp.com/advisory/ntap-20220915-0009/","https://sqlite.org/releaselog/3_39_2.html","https://www.sqlite.org/cves.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-35737","description":"SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API."}]},{"artifact":{"id":"38a6219041f2b78a","cpes":["cpe:2.3:a:apt:apt:1.6.6:*:*:*:*:*:*:*"],"name":"apt","purl":"pkg:deb/ubuntu/apt@1.6.6?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.6.6","language":"","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apt/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/apt/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.conffiles","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/apt.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/apt.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.list","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/apt.list"},{"path":"/var/lib/dpkg/info/apt.postinst","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/apt.postinst"},{"path":"/var/lib/dpkg/info/apt.postrm","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/apt.postrm"},{"path":"/var/lib/dpkg/info/apt.preinst","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/apt.preinst"},{"path":"/var/lib/dpkg/info/apt.prerm","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/apt.prerm"},{"path":"/var/lib/dpkg/info/apt.shlibs","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/apt.shlibs"},{"path":"/var/lib/dpkg/info/apt.triggers","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/apt.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.6.6ubuntu0.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-3462","versionConstraint":"< 1.6.6ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"apt","version":"1.6.6"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-3462","fix":{"state":"fixed","versions":["1.6.6ubuntu0.1"],"available":[{"date":"2019-01-22","kind":"advisory","version":"1.6.6ubuntu0.1"}]},"cvss":[],"epss":[{"cve":"CVE-2019-3462","date":"2026-10-08","epss":0.14555,"percentile":0.96568}],"risk":10.916250000000002,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-3462"},"relatedVulnerabilities":[{"id":"CVE-2019-3462","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":9.3,"impactScore":10.1,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-3462","date":"2026-10-08","epss":0.14555,"percentile":0.96568}],"urls":["http://www.securityfocus.com/bid/106690","https://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/01/msg00013.html","https://lists.debian.org/debian-lts-announce/2019/01/msg00014.html","https://security.netapp.com/advisory/ntap-20190125-0002/","https://usn.ubuntu.com/3863-1/","https://usn.ubuntu.com/3863-2/","https://www.debian.org/security/2019/dsa-4371"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-3462","description":"Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine."}]},{"artifact":{"id":"8e6749ffbd50952e","cpes":["cpe:2.3:a:apt-utils:apt-utils:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:apt-utils:apt_utils:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:apt_utils:apt-utils:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:apt_utils:apt_utils:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:apt:apt-utils:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:apt:apt_utils:1.6.6:*:*:*:*:*:*:*"],"name":"apt-utils","purl":"pkg:deb/ubuntu/apt-utils@1.6.6?arch=amd64&distro=ubuntu-18.04&upstream=apt","type":"deb","version":"1.6.6","language":"","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apt-utils/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/apt-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt-utils.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/apt-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt-utils.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/apt-utils.list"}],"upstreams":[{"name":"apt"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.6.6ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-3462","versionConstraint":"< 1.6.6ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"apt","version":"1.6.6"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-3462","fix":{"state":"fixed","versions":["1.6.6ubuntu0.1"],"available":[{"date":"2019-01-22","kind":"advisory","version":"1.6.6ubuntu0.1"}]},"cvss":[],"epss":[{"cve":"CVE-2019-3462","date":"2026-10-08","epss":0.14555,"percentile":0.96568}],"risk":10.916250000000002,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-3462"},"relatedVulnerabilities":[{"id":"CVE-2019-3462","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":9.3,"impactScore":10.1,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-3462","date":"2026-10-08","epss":0.14555,"percentile":0.96568}],"urls":["http://www.securityfocus.com/bid/106690","https://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/01/msg00013.html","https://lists.debian.org/debian-lts-announce/2019/01/msg00014.html","https://security.netapp.com/advisory/ntap-20190125-0002/","https://usn.ubuntu.com/3863-1/","https://usn.ubuntu.com/3863-2/","https://www.debian.org/security/2019/dsa-4371"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-3462","description":"Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine."}]},{"artifact":{"id":"cf69ae3f468a709f","cpes":["cpe:2.3:a:libapt-inst2.0:libapt-inst2.0:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:libapt-inst2.0:libapt_inst2.0:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:libapt_inst2.0:libapt-inst2.0:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:libapt_inst2.0:libapt_inst2.0:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt-inst2.0:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt_inst2.0:1.6.6:*:*:*:*:*:*:*"],"name":"libapt-inst2.0","purl":"pkg:deb/ubuntu/libapt-inst2.0@1.6.6?arch=amd64&distro=ubuntu-18.04&upstream=apt","type":"deb","version":"1.6.6","language":"","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libapt-inst2.0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libapt-inst2.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libapt-inst2.0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libapt-inst2.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"apt"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.6.6ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-3462","versionConstraint":"< 1.6.6ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"apt","version":"1.6.6"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-3462","fix":{"state":"fixed","versions":["1.6.6ubuntu0.1"],"available":[{"date":"2019-01-22","kind":"advisory","version":"1.6.6ubuntu0.1"}]},"cvss":[],"epss":[{"cve":"CVE-2019-3462","date":"2026-10-08","epss":0.14555,"percentile":0.96568}],"risk":10.916250000000002,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-3462"},"relatedVulnerabilities":[{"id":"CVE-2019-3462","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":9.3,"impactScore":10.1,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-3462","date":"2026-10-08","epss":0.14555,"percentile":0.96568}],"urls":["http://www.securityfocus.com/bid/106690","https://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/01/msg00013.html","https://lists.debian.org/debian-lts-announce/2019/01/msg00014.html","https://security.netapp.com/advisory/ntap-20190125-0002/","https://usn.ubuntu.com/3863-1/","https://usn.ubuntu.com/3863-2/","https://www.debian.org/security/2019/dsa-4371"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-3462","description":"Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine."}]},{"artifact":{"id":"69948ac81b2aa639","cpes":["cpe:2.3:a:libapt-pkg5.0:libapt-pkg5.0:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:libapt-pkg5.0:libapt_pkg5.0:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg5.0:libapt-pkg5.0:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg5.0:libapt_pkg5.0:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt-pkg5.0:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt_pkg5.0:1.6.6:*:*:*:*:*:*:*"],"name":"libapt-pkg5.0","purl":"pkg:deb/ubuntu/libapt-pkg5.0@1.6.6?arch=amd64&distro=ubuntu-18.04&upstream=apt","type":"deb","version":"1.6.6","language":"","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libapt-pkg5.0/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libapt-pkg5.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libapt-pkg5.0:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libapt-pkg5.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"apt"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.6.6ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-3462","versionConstraint":"< 1.6.6ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"apt","version":"1.6.6"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-3462","fix":{"state":"fixed","versions":["1.6.6ubuntu0.1"],"available":[{"date":"2019-01-22","kind":"advisory","version":"1.6.6ubuntu0.1"}]},"cvss":[],"epss":[{"cve":"CVE-2019-3462","date":"2026-10-08","epss":0.14555,"percentile":0.96568}],"risk":10.916250000000002,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-3462"},"relatedVulnerabilities":[{"id":"CVE-2019-3462","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":9.3,"impactScore":10.1,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-3462","date":"2026-10-08","epss":0.14555,"percentile":0.96568}],"urls":["http://www.securityfocus.com/bid/106690","https://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/01/msg00013.html","https://lists.debian.org/debian-lts-announce/2019/01/msg00014.html","https://security.netapp.com/advisory/ntap-20190125-0002/","https://usn.ubuntu.com/3863-1/","https://usn.ubuntu.com/3863-2/","https://www.debian.org/security/2019/dsa-4371"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-3462","description":"Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.13"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-24329","versionConstraint":"< 2.7.17-1~18.04ubuntu1.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-24329","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.13"],"available":[{"date":"2023-02-17","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24329","date":"2026-10-08","epss":0.20459,"percentile":0.9745}],"risk":10.2295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-24329"},"relatedVulnerabilities":[{"id":"CVE-2023-24329","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24329","date":"2026-10-08","epss":0.20459,"percentile":0.9745}],"urls":["https://github.com/python/cpython/issues/102153","https://github.com/python/cpython/pull/99421","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6PEVICI7YNGGMSL3UCMWGE66QFLATH72/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSL6NSOAXWBJJ67XPLSSC74MNKZF3BBO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EM2XLZSTXG44TMFXF4E6VTGKR2MQCW3G/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2NY75GFDZ5T6YPN44D3VMFT5SUVTOTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GR5US3BYILYJ4SKBV6YBNPRUBAL5P2CN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H23OSKC6UG6IWOQAUPW74YUHWRWVXJP7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZTLGV2HYFF4AMYJL25VDIGAIHCU7UPA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWC4WGXER5P6Q75RFGL7QUTPP3N5JR7T/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZEHSXSCMA4WWQKXT6QV7AAR6SWNZ2VP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O5SP4RT3RRS434ZS2HQKQJ3VZW7YPKYR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHHJHJRLEF3TDT2K3676CAUVRDD4CCMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PEUN6T22UJFXR7J5F6UUHCXXPKJ2DVHI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PURM5CFDABEWAIWZFD2MQ7ZJGCPYSQ44/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q3J5N24ECS4B6MJDRO6UAYU6GPLYBDCL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QRQHN7RWJQJHYP6E5EKESOYP5VDSHZG4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RA2MBEEES6L46OD64OBSVUUMGKNGMOWW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4IDB5OAR5Y4UK3HLMZBW4WEL2B7YFMJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TZH26JGNZ5XYPZ5SAU3NKSBSPRE5OHTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2MZOJYGFCB5PPT6AKMAU72N7QOYWLBP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UONZWLB4QVLQIY5CPDLEUEKH6WX4VQMC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTOAUJNDWZDRWVSXJ354AYZYKRMT56HU/","https://pointernull.com/security/python-url-parse-problem.html","https://security.netapp.com/advisory/ntap-20230324-0004/","https://www.kb.cert.org/vuls/id/127587","https://lists.debian.org/debian-lts-announce/2024/11/msg00005.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24329","description":"An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.13"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-24329","versionConstraint":"< 2.7.17-1~18.04ubuntu1.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-24329","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.13"],"available":[{"date":"2023-02-17","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24329","date":"2026-10-08","epss":0.20459,"percentile":0.9745}],"risk":10.2295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-24329"},"relatedVulnerabilities":[{"id":"CVE-2023-24329","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24329","date":"2026-10-08","epss":0.20459,"percentile":0.9745}],"urls":["https://github.com/python/cpython/issues/102153","https://github.com/python/cpython/pull/99421","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6PEVICI7YNGGMSL3UCMWGE66QFLATH72/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSL6NSOAXWBJJ67XPLSSC74MNKZF3BBO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EM2XLZSTXG44TMFXF4E6VTGKR2MQCW3G/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2NY75GFDZ5T6YPN44D3VMFT5SUVTOTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GR5US3BYILYJ4SKBV6YBNPRUBAL5P2CN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H23OSKC6UG6IWOQAUPW74YUHWRWVXJP7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZTLGV2HYFF4AMYJL25VDIGAIHCU7UPA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWC4WGXER5P6Q75RFGL7QUTPP3N5JR7T/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZEHSXSCMA4WWQKXT6QV7AAR6SWNZ2VP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O5SP4RT3RRS434ZS2HQKQJ3VZW7YPKYR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHHJHJRLEF3TDT2K3676CAUVRDD4CCMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PEUN6T22UJFXR7J5F6UUHCXXPKJ2DVHI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PURM5CFDABEWAIWZFD2MQ7ZJGCPYSQ44/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q3J5N24ECS4B6MJDRO6UAYU6GPLYBDCL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QRQHN7RWJQJHYP6E5EKESOYP5VDSHZG4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RA2MBEEES6L46OD64OBSVUUMGKNGMOWW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4IDB5OAR5Y4UK3HLMZBW4WEL2B7YFMJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TZH26JGNZ5XYPZ5SAU3NKSBSPRE5OHTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2MZOJYGFCB5PPT6AKMAU72N7QOYWLBP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UONZWLB4QVLQIY5CPDLEUEKH6WX4VQMC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTOAUJNDWZDRWVSXJ354AYZYKRMT56HU/","https://pointernull.com/security/python-url-parse-problem.html","https://security.netapp.com/advisory/ntap-20230324-0004/","https://www.kb.cert.org/vuls/id/127587","https://lists.debian.org/debian-lts-announce/2024/11/msg00005.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24329","description":"An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-24329","versionConstraint":"< 2.7.17-1~18.04ubuntu1.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-24329","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.13"],"available":[{"date":"2023-02-17","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24329","date":"2026-10-08","epss":0.20459,"percentile":0.9745}],"risk":10.2295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-24329"},"relatedVulnerabilities":[{"id":"CVE-2023-24329","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24329","date":"2026-10-08","epss":0.20459,"percentile":0.9745}],"urls":["https://github.com/python/cpython/issues/102153","https://github.com/python/cpython/pull/99421","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6PEVICI7YNGGMSL3UCMWGE66QFLATH72/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSL6NSOAXWBJJ67XPLSSC74MNKZF3BBO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EM2XLZSTXG44TMFXF4E6VTGKR2MQCW3G/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2NY75GFDZ5T6YPN44D3VMFT5SUVTOTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GR5US3BYILYJ4SKBV6YBNPRUBAL5P2CN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H23OSKC6UG6IWOQAUPW74YUHWRWVXJP7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZTLGV2HYFF4AMYJL25VDIGAIHCU7UPA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWC4WGXER5P6Q75RFGL7QUTPP3N5JR7T/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZEHSXSCMA4WWQKXT6QV7AAR6SWNZ2VP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O5SP4RT3RRS434ZS2HQKQJ3VZW7YPKYR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHHJHJRLEF3TDT2K3676CAUVRDD4CCMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PEUN6T22UJFXR7J5F6UUHCXXPKJ2DVHI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PURM5CFDABEWAIWZFD2MQ7ZJGCPYSQ44/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q3J5N24ECS4B6MJDRO6UAYU6GPLYBDCL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QRQHN7RWJQJHYP6E5EKESOYP5VDSHZG4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RA2MBEEES6L46OD64OBSVUUMGKNGMOWW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4IDB5OAR5Y4UK3HLMZBW4WEL2B7YFMJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TZH26JGNZ5XYPZ5SAU3NKSBSPRE5OHTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2MZOJYGFCB5PPT6AKMAU72N7QOYWLBP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UONZWLB4QVLQIY5CPDLEUEKH6WX4VQMC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTOAUJNDWZDRWVSXJ354AYZYKRMT56HU/","https://pointernull.com/security/python-url-parse-problem.html","https://security.netapp.com/advisory/ntap-20230324-0004/","https://www.kb.cert.org/vuls/id/127587","https://lists.debian.org/debian-lts-announce/2024/11/msg00005.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24329","description":"An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.13"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-24329","versionConstraint":"< 2.7.17-1~18.04ubuntu1.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-24329","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.13"],"available":[{"date":"2023-02-17","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24329","date":"2026-10-08","epss":0.20459,"percentile":0.9745}],"risk":10.2295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-24329"},"relatedVulnerabilities":[{"id":"CVE-2023-24329","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24329","date":"2026-10-08","epss":0.20459,"percentile":0.9745}],"urls":["https://github.com/python/cpython/issues/102153","https://github.com/python/cpython/pull/99421","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6PEVICI7YNGGMSL3UCMWGE66QFLATH72/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSL6NSOAXWBJJ67XPLSSC74MNKZF3BBO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EM2XLZSTXG44TMFXF4E6VTGKR2MQCW3G/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2NY75GFDZ5T6YPN44D3VMFT5SUVTOTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GR5US3BYILYJ4SKBV6YBNPRUBAL5P2CN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H23OSKC6UG6IWOQAUPW74YUHWRWVXJP7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZTLGV2HYFF4AMYJL25VDIGAIHCU7UPA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWC4WGXER5P6Q75RFGL7QUTPP3N5JR7T/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZEHSXSCMA4WWQKXT6QV7AAR6SWNZ2VP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O5SP4RT3RRS434ZS2HQKQJ3VZW7YPKYR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHHJHJRLEF3TDT2K3676CAUVRDD4CCMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PEUN6T22UJFXR7J5F6UUHCXXPKJ2DVHI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PURM5CFDABEWAIWZFD2MQ7ZJGCPYSQ44/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q3J5N24ECS4B6MJDRO6UAYU6GPLYBDCL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QRQHN7RWJQJHYP6E5EKESOYP5VDSHZG4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RA2MBEEES6L46OD64OBSVUUMGKNGMOWW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4IDB5OAR5Y4UK3HLMZBW4WEL2B7YFMJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TZH26JGNZ5XYPZ5SAU3NKSBSPRE5OHTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2MZOJYGFCB5PPT6AKMAU72N7QOYWLBP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UONZWLB4QVLQIY5CPDLEUEKH6WX4VQMC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTOAUJNDWZDRWVSXJ354AYZYKRMT56HU/","https://pointernull.com/security/python-url-parse-problem.html","https://security.netapp.com/advisory/ntap-20230324-0004/","https://www.kb.cert.org/vuls/id/127587","https://lists.debian.org/debian-lts-announce/2024/11/msg00005.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24329","description":"An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.21"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-4450","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-4450","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.21"],"available":[{"date":"2023-02-07","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-4450","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4450","cwe":"CWE-415","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4450","date":"2026-10-08","epss":0.20287,"percentile":0.97419}],"risk":10.1435,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-4450"},"relatedVulnerabilities":[{"id":"CVE-2022-4450","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4450","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4450","cwe":"CWE-415","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4450","date":"2026-10-08","epss":0.20287,"percentile":0.97419}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=63bcf189be73a9cc1264059bed6f57974be74a83","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=bbcf509bd046b34cca19c766bbddc31683d0858b","https://security.gentoo.org/glsa/202402-08","https://www.openssl.org/news/secadv/20230207.txt","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-4450","description":"The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and\ndecodes the \"name\" (e.g. \"CERTIFICATE\"), any header data and the payload data.\nIf the function succeeds then the \"name_out\", \"header\" and \"data\" arguments are\npopulated with pointers to buffers containing the relevant decoded data. The\ncaller is responsible for freeing those buffers. It is possible to construct a\nPEM file that results in 0 bytes of payload data. In this case PEM_read_bio_ex()\nwill return a failure code but will populate the header argument with a pointer\nto a buffer that has already been freed. If the caller also frees this buffer\nthen a double free will occur. This will most likely lead to a crash. This\ncould be exploited by an attacker who has the ability to supply malicious PEM\nfiles for parsing to achieve a denial of service attack.\n\nThe functions PEM_read_bio() and PEM_read() are simple wrappers around\nPEM_read_bio_ex() and therefore these functions are also directly affected.\n\nThese functions are also called indirectly by a number of other OpenSSL\nfunctions including PEM_X509_INFO_read_bio_ex() and\nSSL_CTX_use_serverinfo_file() which are also vulnerable. Some OpenSSL internal\nuses of these functions are not vulnerable because the caller does not free the\nheader argument if PEM_read_bio_ex() returns a failure code. These locations\ninclude the PEM_read_bio_TYPE() functions as well as the decoders introduced in\nOpenSSL 3.0.\n\nThe OpenSSL asn1parse command line application is also impacted by this issue."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.21"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-4450","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-4450","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.21"],"available":[{"date":"2023-02-07","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-4450","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4450","cwe":"CWE-415","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4450","date":"2026-10-08","epss":0.20287,"percentile":0.97419}],"risk":10.1435,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-4450"},"relatedVulnerabilities":[{"id":"CVE-2022-4450","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4450","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4450","cwe":"CWE-415","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4450","date":"2026-10-08","epss":0.20287,"percentile":0.97419}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=63bcf189be73a9cc1264059bed6f57974be74a83","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=bbcf509bd046b34cca19c766bbddc31683d0858b","https://security.gentoo.org/glsa/202402-08","https://www.openssl.org/news/secadv/20230207.txt","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-4450","description":"The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and\ndecodes the \"name\" (e.g. \"CERTIFICATE\"), any header data and the payload data.\nIf the function succeeds then the \"name_out\", \"header\" and \"data\" arguments are\npopulated with pointers to buffers containing the relevant decoded data. The\ncaller is responsible for freeing those buffers. It is possible to construct a\nPEM file that results in 0 bytes of payload data. In this case PEM_read_bio_ex()\nwill return a failure code but will populate the header argument with a pointer\nto a buffer that has already been freed. If the caller also frees this buffer\nthen a double free will occur. This will most likely lead to a crash. This\ncould be exploited by an attacker who has the ability to supply malicious PEM\nfiles for parsing to achieve a denial of service attack.\n\nThe functions PEM_read_bio() and PEM_read() are simple wrappers around\nPEM_read_bio_ex() and therefore these functions are also directly affected.\n\nThese functions are also called indirectly by a number of other OpenSSL\nfunctions including PEM_X509_INFO_read_bio_ex() and\nSSL_CTX_use_serverinfo_file() which are also vulnerable. Some OpenSSL internal\nuses of these functions are not vulnerable because the caller does not free the\nheader argument if PEM_read_bio_ex() returns a failure code. These locations\ninclude the PEM_read_bio_TYPE() functions as well as the decoders introduced in\nOpenSSL 3.0.\n\nThe OpenSSL asn1parse command line application is also impacted by this issue."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h822-r4r5-v8jg","versionConstraint":">=2.9.0,<2.9.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-h822-r4r5-v8jg","fix":{"state":"fixed","versions":["2.9.10"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14540","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14540","date":"2026-10-08","epss":0.10763,"percentile":0.95731}],"risk":10.11722,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-14540","https://github.com/FasterXML/jackson-databind/blob/master/release-notes/VERSION-2.x","https://github.com/FasterXML/jackson-databind/issues/2410","https://github.com/FasterXML/jackson-databind/issues/2449","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69@%3Ccommits.tinkerpop.apache.org%3E","https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/a360b46061c91c5cad789b6c3190aef9b9f223a2b75c9c9f046fe016@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/a4f2c9fb36642a48912cdec6836ec00e497427717c5d377f8d7ccce6@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ad0d238e97a7da5eca47a014f0f7e81f440ed6bf74a93183825e18b9@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/dc6b5cad721a4f6b3b62ed1163894941140d9d5656140fb757505ca0@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/e90c3feb21702e68a8c08afce37045adb3870f2bf8223fa403fb93fb@%3Ccommits.hbase.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://seclists.org/bugtraq/2019/Oct/6","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/d4983c740fec7d5576b207a8c30a63d3ea7443de","https://github.com/FasterXML/jackson-databind/commit/73c1c2cc76e6cdd7f3a5615cbe3207fe96e4d3db","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT","https://security.netapp.com/advisory/ntap-20191004-0002"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h822-r4r5-v8jg","description":"Polymorphic Typing issue in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-14540","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14540","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14540","date":"2026-10-08","epss":0.10763,"percentile":0.95731}],"urls":["https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://github.com/FasterXML/jackson-databind/blob/master/release-notes/VERSION-2.x","https://github.com/FasterXML/jackson-databind/issues/2410","https://github.com/FasterXML/jackson-databind/issues/2449","https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69%40%3Ccommits.tinkerpop.apache.org%3E","https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1%40%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/a360b46061c91c5cad789b6c3190aef9b9f223a2b75c9c9f046fe016%40%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/a4f2c9fb36642a48912cdec6836ec00e497427717c5d377f8d7ccce6%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ad0d238e97a7da5eca47a014f0f7e81f440ed6bf74a93183825e18b9%40%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/dc6b5cad721a4f6b3b62ed1163894941140d9d5656140fb757505ca0%40%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/e90c3feb21702e68a8c08afce37045adb3870f2bf8223fa403fb93fb%40%3Ccommits.hbase.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20191004-0002/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-14540","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c8hm-7hpq-7jhg","versionConstraint":">=2.9.0,<2.9.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c8hm-7hpq-7jhg","fix":{"state":"fixed","versions":["2.9.8"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19362","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19362","date":"2026-10-08","epss":0.10599,"percentile":0.95683}],"risk":9.963060000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-19362","https://github.com/FasterXML/jackson-databind/issues/2186","https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8","https://issues.apache.org/jira/browse/TINKERPOP-2121","https://lists.apache.org/thread.html/37e1ed724a1b0e5d191d98c822c426670bdfde83804567131847d2a3@%3Cdevnull.infra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/c70da3cb6e3f03e0ad8013e38b6959419d866c4a7c80fdd34b73f25c@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","http://www.securityfocus.com/bid/107985","https://github.com/FasterXML/jackson-databind/commit/72cd4025a229fb28ec133235003dd4616f70afaa","https://security.netapp.com/advisory/ntap-20190530-0003"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c8hm-7hpq-7jhg","description":"com.fasterxml.jackson.core:jackson-databind vulnerable to Deserialization of Untrusted Data"},"relatedVulnerabilities":[{"id":"CVE-2018-19362","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19362","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19362","date":"2026-10-08","epss":0.10599,"percentile":0.95683}],"urls":["http://www.securityfocus.com/bid/107985","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b","https://github.com/FasterXML/jackson-databind/issues/2186","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8","https://issues.apache.org/jira/browse/TINKERPOP-2121","https://lists.apache.org/thread.html/37e1ed724a1b0e5d191d98c822c426670bdfde83804567131847d2a3%40%3Cdevnull.infra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/c70da3cb6e3f03e0ad8013e38b6959419d866c4a7c80fdd34b73f25c%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19362","description":"FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f9hv-mg5h-xcw9","versionConstraint":">=2.9.0,<2.9.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-f9hv-mg5h-xcw9","fix":{"state":"fixed","versions":["2.9.8"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19360","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19360","date":"2026-10-08","epss":0.10599,"percentile":0.95683}],"risk":9.963060000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-19360","https://github.com/FasterXML/jackson-databind/issues/2186","https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8","https://issues.apache.org/jira/browse/TINKERPOP-2121","https://lists.apache.org/thread.html/37e1ed724a1b0e5d191d98c822c426670bdfde83804567131847d2a3@%3Cdevnull.infra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/c70da3cb6e3f03e0ad8013e38b6959419d866c4a7c80fdd34b73f25c@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","http://www.securityfocus.com/bid/107985"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f9hv-mg5h-xcw9","description":"Deserialization of Untrusted Data in jackson-databind due to polymorphic deserialization"},"relatedVulnerabilities":[{"id":"CVE-2018-19360","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19360","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19360","date":"2026-10-08","epss":0.10599,"percentile":0.95683}],"urls":["http://www.securityfocus.com/bid/107985","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b","https://github.com/FasterXML/jackson-databind/issues/2186","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8","https://issues.apache.org/jira/browse/TINKERPOP-2121","https://lists.apache.org/thread.html/37e1ed724a1b0e5d191d98c822c426670bdfde83804567131847d2a3%40%3Cdevnull.infra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/c70da3cb6e3f03e0ad8013e38b6959419d866c4a7c80fdd34b73f25c%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19360","description":"FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mx9v-gmh4-mgqw","versionConstraint":">=2.9.0,<2.9.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mx9v-gmh4-mgqw","fix":{"state":"fixed","versions":["2.9.8"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19361","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19361","date":"2026-10-08","epss":0.10599,"percentile":0.95682}],"risk":9.963060000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-19361","https://github.com/FasterXML/jackson-databind/issues/2186","https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8","https://issues.apache.org/jira/browse/TINKERPOP-2121","https://lists.apache.org/thread.html/37e1ed724a1b0e5d191d98c822c426670bdfde83804567131847d2a3@%3Cdevnull.infra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/c70da3cb6e3f03e0ad8013e38b6959419d866c4a7c80fdd34b73f25c@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","http://www.securityfocus.com/bid/107985"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mx9v-gmh4-mgqw","description":"Deserialization of Untrusted Data in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2018-19361","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19361","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19361","date":"2026-10-08","epss":0.10599,"percentile":0.95682}],"urls":["http://www.securityfocus.com/bid/107985","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b","https://github.com/FasterXML/jackson-databind/issues/2186","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8","https://issues.apache.org/jira/browse/TINKERPOP-2121","https://lists.apache.org/thread.html/37e1ed724a1b0e5d191d98c822c426670bdfde83804567131847d2a3%40%3Cdevnull.infra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/c70da3cb6e3f03e0ad8013e38b6959419d866c4a7c80fdd34b73f25c%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19361","description":"FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9mxf-g3x6-wv74","versionConstraint":">=2.9.0,<2.9.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-9mxf-g3x6-wv74","fix":{"state":"fixed","versions":["2.9.7"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-14721","cwe":"CWE-918","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-14721","date":"2026-10-08","epss":0.10458,"percentile":0.95639}],"risk":9.9351,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-14721","https://github.com/FasterXML/jackson-databind/issues/2097","https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:1106","https://access.redhat.com/errata/RHSA-2019:1107","https://access.redhat.com/errata/RHSA-2019:1108","https://access.redhat.com/errata/RHSA-2019:1140","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9mxf-g3x6-wv74","description":"Server-Side Request Forgery (SSRF) in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2018-14721","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-14721","cwe":"CWE-918","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-14721","date":"2026-10-08","epss":0.10458,"percentile":0.95639}],"urls":["https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:1106","https://access.redhat.com/errata/RHSA-2019:1107","https://access.redhat.com/errata/RHSA-2019:1108","https://access.redhat.com/errata/RHSA-2019:1140","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44","https://github.com/FasterXML/jackson-databind/issues/2097","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-14721","description":"FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5r5r-6hpj-8gg9","versionConstraint":">=2.0.0,<=2.9.10.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5r5r-6hpj-8gg9","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2023-11-22","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-35728","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-35728","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-35728","date":"2026-10-08","epss":0.12504,"percentile":0.9613}],"risk":9.753120000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-35728","https://github.com/FasterXML/jackson-databind/issues/2999","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210129-0007/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/1ca0388c2fb37ac6a06f1c188ae89c41e3e15e84"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5r5r-6hpj-8gg9","description":"Serialization gadget exploit in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-35728","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-35728","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-35728","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-35728","date":"2026-10-08","epss":0.12504,"percentile":0.9613}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2999","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210129-0007/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-35728","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl)."}]},{"artifact":{"id":"c1103d6297198441","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.11.dfsg-0ubuntu2:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.2.11.dfsg-0ubuntu2?arch=amd64&distro=ubuntu-18.04&upstream=zlib","type":"deb","version":"1:1.2.11.dfsg-0ubuntu2","language":"","licenses":["sha256:176de9c848d59ea736369969db73dcbe025da6360dfba52ad034b52d9616b7c3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"fix":{"suggestedVersion":"1:1.2.11.dfsg-0ubuntu2.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-37434","versionConstraint":"< 1:1.2.11.dfsg-0ubuntu2.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"zlib","version":"1:1.2.11.dfsg-0ubuntu2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-37434","fix":{"state":"fixed","versions":["1:1.2.11.dfsg-0ubuntu2.2"],"available":[{"date":"2022-08-17","kind":"advisory","version":"1:1.2.11.dfsg-0ubuntu2.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-37434","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-37434","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-37434","date":"2026-10-08","epss":0.18972,"percentile":0.97237}],"risk":9.486,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-37434"},"relatedVulnerabilities":[{"id":"CVE-2022-37434","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-37434","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-37434","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-37434","date":"2026-10-08","epss":0.18972,"percentile":0.97237}],"urls":["http://seclists.org/fulldisclosure/2022/Oct/37","http://seclists.org/fulldisclosure/2022/Oct/38","http://seclists.org/fulldisclosure/2022/Oct/41","http://seclists.org/fulldisclosure/2022/Oct/42","http://www.openwall.com/lists/oss-security/2022/08/05/2","http://www.openwall.com/lists/oss-security/2022/08/09/1","https://github.com/curl/curl/issues/9271","https://github.com/ivd38/zlib_overflow","https://github.com/madler/zlib/blob/21767c654d31d2dccdde4330529775c6c5fd5389/zlib.h#L1062-L1063","https://github.com/madler/zlib/commit/1eb7682f845ac9e9bf9ae35bbfb3bad5dacbd91d","https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1","https://github.com/nodejs/node/blob/75b68c6e4db515f76df73af476eccf382bbcb00a/deps/zlib/inflate.c#L762-L764","https://lists.debian.org/debian-lts-announce/2022/09/msg00012.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWN4VE3JQR4O2SOUS5TXNLANRPMHWV4I/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMBOJ77A7T7PQCARMDUK75TE6LLESZ3O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAVPQNCG3XRLCLNSQRM3KAN5ZFMVXVTY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5U7OTKZSHY2I3ZFJSR2SHFHW72RKGDK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YRQAI7H4M4RQZ2IWZUEEXECBE5D56BH2/","https://security.netapp.com/advisory/ntap-20220901-0005/","https://security.netapp.com/advisory/ntap-20230427-0007/","https://support.apple.com/kb/HT213488","https://support.apple.com/kb/HT213489","https://support.apple.com/kb/HT213490","https://support.apple.com/kb/HT213491","https://support.apple.com/kb/HT213493","https://support.apple.com/kb/HT213494","https://www.debian.org/security/2022/dsa-5218","https://cert-portal.siemens.com/productcert/html/ssa-150063.html","https://cert-portal.siemens.com/productcert/html/ssa-202008.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-470355.html","https://cert-portal.siemens.com/productcert/html/ssa-561322.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-37434","description":"zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference)."}]},{"artifact":{"id":"366ad4b4172c8e06","cpes":["cpe:2.3:a:com.google.code.gson:gson:2.7:*:*:*:*:*:*:*","cpe:2.3:a:com.google.gson:gson:2.7:*:*:*:*:*:*:*","cpe:2.3:a:google:gson:2.7:*:*:*:*:*:*:*","cpe:2.3:a:code:gson:2.7:*:*:*:*:*:*:*","cpe:2.3:a:gson:gson:2.7:*:*:*:*:*:*:*"],"name":"gson","purl":"pkg:maven/com.google.code.gson/gson@2.7","type":"java-archive","version":"2.7","language":"java","licenses":[],"metadata":{"pomGroupID":"com.google.code.gson","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/gson-2.7.jar","manifestName":"","pomArtifactID":"gson","archiveDigests":[{"value":"751f548c85fa49f330cecbb1875893f971b33c4e","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/gson-2.7.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.8.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4jrv-ppp4-jm57","versionConstraint":"<2.8.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.google.code.gson:gson","version":"2.7"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4jrv-ppp4-jm57","fix":{"state":"fixed","versions":["2.8.9"],"available":[{"date":"2022-05-21","kind":"first-observed","version":"2.8.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25647","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25647","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25647","date":"2026-10-08","epss":0.1223,"percentile":0.96079}],"risk":9.2948,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-25647","https://github.com/google/gson/pull/1991","https://github.com/google/gson/pull/1991/commits","https://snyk.io/vuln/SNYK-JAVA-COMGOOGLECODEGSON-1730327","https://lists.debian.org/debian-lts-announce/2022/05/msg00015.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://lists.debian.org/debian-lts-announce/2022/09/msg00009.html","https://www.debian.org/security/2022/dsa-5227","https://security.netapp.com/advisory/ntap-20220901-0009"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4jrv-ppp4-jm57","description":"Deserialization of Untrusted Data in Gson"},"relatedVulnerabilities":[{"id":"CVE-2022-25647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25647","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25647","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25647","date":"2026-10-08","epss":0.1223,"percentile":0.96079}],"urls":["https://github.com/google/gson/pull/1991","https://github.com/google/gson/pull/1991/commits","https://lists.debian.org/debian-lts-announce/2022/05/msg00015.html","https://lists.debian.org/debian-lts-announce/2022/09/msg00009.html","https://security.netapp.com/advisory/ntap-20220901-0009/","https://snyk.io/vuln/SNYK-JAVA-COMGOOGLECODEGSON-1730327","https://www.debian.org/security/2022/dsa-5227","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25647","description":"The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4gq5-ch57-c2mg","versionConstraint":">=2.9.0,<2.9.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4gq5-ch57-c2mg","fix":{"state":"fixed","versions":["2.9.7"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-14719","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-14719","date":"2026-10-08","epss":0.09682,"percentile":0.95391}],"risk":9.10108,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-14719","https://github.com/FasterXML/jackson-databind/issues/2097","https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4gq5-ch57-c2mg","description":"Arbitrary Code Execution in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2018-14719","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-14719","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-14719","date":"2026-10-08","epss":0.09682,"percentile":0.95391}],"urls":["https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44","https://github.com/FasterXML/jackson-databind/issues/2097","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-14719","description":"FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization."}]},{"artifact":{"id":"13a9ac46d72c9ab7","cpes":["cpe:2.3:a:unzip:unzip:6.0-21ubuntu1:*:*:*:*:*:*:*"],"name":"unzip","purl":"pkg:deb/ubuntu/unzip@6.0-21ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"6.0-21ubuntu1","language":"","licenses":["sha256:e4864130ae7765aa9424f558ca7ca8fa01c1674344ab83e4ceec749ccda76980"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/unzip/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/unzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/unzip.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/unzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/unzip.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/unzip.list"},{"path":"/var/lib/dpkg/info/unzip.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/unzip.postinst"},{"path":"/var/lib/dpkg/info/unzip.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/unzip.postrm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.0-21ubuntu1.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-1000035","versionConstraint":"< 6.0-21ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"unzip","version":"6.0-21ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-1000035","fix":{"state":"fixed","versions":["6.0-21ubuntu1.1"],"available":[{"date":"2020-12-16","kind":"advisory","version":"6.0-21ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1000035","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000035","date":"2026-10-08","epss":0.30066,"percentile":0.98175}],"risk":9.019799999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1000035"},"relatedVulnerabilities":[{"id":"CVE-2018-1000035","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000035","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000035","date":"2026-10-08","epss":0.30066,"percentile":0.98175}],"urls":["https://lists.debian.org/debian-lts-announce/2020/01/msg00026.html","https://sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-infozip-unzip/index.html","https://security.gentoo.org/glsa/202003-58"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000035","description":"A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-5482","versionConstraint":"< 7.58.0-2ubuntu3.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-5482","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.8"],"available":[{"date":"2019-09-11","kind":"advisory","version":"7.58.0-2ubuntu3.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5482","cwe":"CWE-122","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2019-5482","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5482","date":"2026-10-08","epss":0.17939,"percentile":0.97115}],"risk":8.9695,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5482"},"relatedVulnerabilities":[{"id":"CVE-2019-5482","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5482","cwe":"CWE-122","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2019-5482","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5482","date":"2026-10-08","epss":0.17939,"percentile":0.97115}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00048.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00055.html","https://curl.haxx.se/docs/CVE-2019-5482.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CI4QQ2RSZX4VCFM76SIWGKY6BY7UWIC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGDVKSLY5JUNJRLYRUA6CXGQ2LM63XC3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UA7KDM2WPM5CJDDGOEGFV6SSGD2J7RNT/","https://seclists.org/bugtraq/2020/Feb/36","https://security.gentoo.org/glsa/202003-29","https://security.netapp.com/advisory/ntap-20191004-0003/","https://security.netapp.com/advisory/ntap-20200416-0003/","https://www.debian.org/security/2020/dsa-4633","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5482","description":"Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-5482","versionConstraint":"< 7.58.0-2ubuntu3.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-5482","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.8"],"available":[{"date":"2019-09-11","kind":"advisory","version":"7.58.0-2ubuntu3.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5482","cwe":"CWE-122","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2019-5482","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5482","date":"2026-10-08","epss":0.17939,"percentile":0.97115}],"risk":8.9695,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5482"},"relatedVulnerabilities":[{"id":"CVE-2019-5482","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5482","cwe":"CWE-122","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2019-5482","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5482","date":"2026-10-08","epss":0.17939,"percentile":0.97115}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00048.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00055.html","https://curl.haxx.se/docs/CVE-2019-5482.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CI4QQ2RSZX4VCFM76SIWGKY6BY7UWIC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGDVKSLY5JUNJRLYRUA6CXGQ2LM63XC3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UA7KDM2WPM5CJDDGOEGFV6SSGD2J7RNT/","https://seclists.org/bugtraq/2020/Feb/36","https://security.gentoo.org/glsa/202003-29","https://security.netapp.com/advisory/ntap-20191004-0003/","https://security.netapp.com/advisory/ntap-20200416-0003/","https://www.debian.org/security/2020/dsa-4633","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5482","description":"Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-7264","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-7264","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-7264","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7264","date":"2026-10-08","epss":0.17301,"percentile":0.9704}],"risk":8.6505,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-7264"},"relatedVulnerabilities":[{"id":"CVE-2024-7264","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7264","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7264","date":"2026-10-08","epss":0.17301,"percentile":0.9704}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/31/1","https://curl.se/docs/CVE-2024-7264.html","https://curl.se/docs/CVE-2024-7264.json","https://hackerone.com/reports/2629968","https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519","https://security.netapp.com/advisory/ntap-20240828-0008/","https://security.netapp.com/advisory/ntap-20241025-0006/","https://security.netapp.com/advisory/ntap-20241025-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-7264","description":"libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-7264","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-7264","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-7264","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7264","date":"2026-10-08","epss":0.17301,"percentile":0.9704}],"risk":8.6505,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-7264"},"relatedVulnerabilities":[{"id":"CVE-2024-7264","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7264","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7264","date":"2026-10-08","epss":0.17301,"percentile":0.9704}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/31/1","https://curl.se/docs/CVE-2024-7264.html","https://curl.se/docs/CVE-2024-7264.json","https://hackerone.com/reports/2629968","https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519","https://security.netapp.com/advisory/ntap-20240828-0008/","https://security.netapp.com/advisory/ntap-20241025-0006/","https://security.netapp.com/advisory/ntap-20241025-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-7264","description":"libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gww7-p5w4-wrfv","versionConstraint":">=2.9.0,<=2.9.10.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gww7-p5w4-wrfv","fix":{"state":"fixed","versions":["2.9.10.2"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-20330","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20330","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20330","date":"2026-10-08","epss":0.0864,"percentile":0.94984}],"risk":8.1216,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-20330","https://github.com/FasterXML/jackson-databind/issues/2526","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.10.1...jackson-databind-2.9.10.2","https://lists.apache.org/thread.html/r107c8737db39ec9ec4f4e7147b249e29be79170b9ef4b80528105a2d@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r2c77dd6ab8344285bd8e481b57cf3029965a4b0036eefccef74cdd44@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r3f8180d0d25a7c6473ebb9714b0c1d19a73f455ae70d0c5fefc17e6c@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r428735963bee7cb99877b88d3228e28ec28af64646455c4f3e7a3c94@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r50f513772f12e1babf65c7c2b9c16425bac2d945351879e2e267517f@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r5c14fdcabdeaba258857bcb67198652e4dce1d33ddc590cd81d82393@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r5c3644c97f0434d1ceb48ff48897a67bdbf3baf7efbe7d04625425b3@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r5d3d10fdf28110da3f9ac1b7d08d7e252f98d7d37ce0a6bd139a2e4f@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r67f4d4c48197454b83d62afbed8bebbda3764e6e3a6e26a848961764@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r707d23bb9ee245f50aa909add0da6e8d8f24719b1278ddd99d2428b2@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r7a0821b44247a1e6c6fe5f2943b90ebc4f80a8d1fb0aa9a8b29a59a2@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r7fb123e7dad49af5886cfec7135c0fd5b74e4c67af029e1dc91ba744@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r8831b7fa5ca87a1cf23ee08d6dedb7877a964c1d2bd869af24056a63@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r909c822409a276ba04dc2ae31179b16f6864ba02c4f9911bdffebf95@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra2e572f568de8df5ba151e6aebb225a0629faaf0476bf7c7ed877af8@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra5ce96faec37c26b0aa15b4b6a8b1cbb145a748653e56ae83e9685d0@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra8a80dbc7319916946397823aec0d893d24713cbf7b5aee0e957298c@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb532fed78d031fff477fd840b81946f6d1200f93a63698dae65aa528@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/rd1f346227e11fc515914f3a7b20d81543e51e5822ba71baa0452634a@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd49cfa41bbb71ef33b53736a6af2aa8ba88c2106e30f2a34902a87d2@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd6c6fef14944f3dcfb58d35f9317eb1c32a700e86c1b5231e45d3d0b@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/rfa57d9c2a27d3af14c69607fb1a3da00e758b2092aa88eb6a51b6e99@%3Cissues.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/02/msg00020.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/FasterXML/jackson-databind/commit/eb254813cc822d0af015ce8fe05febf50721dc53","https://github.com/FasterXML/jackson-databind/commit/fc4214a883dc087070f25da738ef0d49c2f3387e","https://security.netapp.com/advisory/ntap-20200127-0004"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gww7-p5w4-wrfv","description":"Deserialization of Untrusted Data in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-20330","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-20330","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20330","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20330","date":"2026-10-08","epss":0.0864,"percentile":0.94984}],"urls":["https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.10.1...jackson-databind-2.9.10.2","https://github.com/FasterXML/jackson-databind/issues/2526","https://lists.apache.org/thread.html/r107c8737db39ec9ec4f4e7147b249e29be79170b9ef4b80528105a2d%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/r2c77dd6ab8344285bd8e481b57cf3029965a4b0036eefccef74cdd44%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r3f8180d0d25a7c6473ebb9714b0c1d19a73f455ae70d0c5fefc17e6c%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r428735963bee7cb99877b88d3228e28ec28af64646455c4f3e7a3c94%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r50f513772f12e1babf65c7c2b9c16425bac2d945351879e2e267517f%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r5c14fdcabdeaba258857bcb67198652e4dce1d33ddc590cd81d82393%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r5c3644c97f0434d1ceb48ff48897a67bdbf3baf7efbe7d04625425b3%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r5d3d10fdf28110da3f9ac1b7d08d7e252f98d7d37ce0a6bd139a2e4f%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r67f4d4c48197454b83d62afbed8bebbda3764e6e3a6e26a848961764%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r707d23bb9ee245f50aa909add0da6e8d8f24719b1278ddd99d2428b2%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r7a0821b44247a1e6c6fe5f2943b90ebc4f80a8d1fb0aa9a8b29a59a2%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r7fb123e7dad49af5886cfec7135c0fd5b74e4c67af029e1dc91ba744%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r8831b7fa5ca87a1cf23ee08d6dedb7877a964c1d2bd869af24056a63%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r909c822409a276ba04dc2ae31179b16f6864ba02c4f9911bdffebf95%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra2e572f568de8df5ba151e6aebb225a0629faaf0476bf7c7ed877af8%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra5ce96faec37c26b0aa15b4b6a8b1cbb145a748653e56ae83e9685d0%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra8a80dbc7319916946397823aec0d893d24713cbf7b5aee0e957298c%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb532fed78d031fff477fd840b81946f6d1200f93a63698dae65aa528%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/rd1f346227e11fc515914f3a7b20d81543e51e5822ba71baa0452634a%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd49cfa41bbb71ef33b53736a6af2aa8ba88c2106e30f2a34902a87d2%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd6c6fef14944f3dcfb58d35f9317eb1c32a700e86c1b5231e45d3d0b%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rfa57d9c2a27d3af14c69607fb1a3da00e758b2092aa88eb6a51b6e99%40%3Cissues.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/02/msg00020.html","https://security.netapp.com/advisory/ntap-20200127-0004/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-20330","description":"FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.21"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-4304","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-4304","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.21"],"available":[{"date":"2023-02-07","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-4304","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4304","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4304","date":"2026-10-08","epss":0.16195,"percentile":0.96865}],"risk":8.0975,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-4304"},"relatedVulnerabilities":[{"id":"CVE-2022-4304","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4304","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4304","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4304","date":"2026-10-08","epss":0.16195,"percentile":0.96865}],"urls":["https://security.gentoo.org/glsa/202402-08","https://www.openssl.org/news/secadv/20230207.txt","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-4304","description":"A timing based side channel exists in the OpenSSL RSA Decryption implementation\nwhich could be sufficient to recover a plaintext across a network in a\nBleichenbacher style attack. To achieve a successful decryption an attacker\nwould have to be able to send a very large number of trial messages for\ndecryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5,\nRSA-OEAP and RSASVE.\n\nFor example, in a TLS connection, RSA is commonly used by a client to send an\nencrypted pre-master secret to the server. An attacker that had observed a\ngenuine connection between a client and a server could use this flaw to send\ntrial messages to the server and record the time taken to process them. After a\nsufficiently large number of messages the attacker could recover the pre-master\nsecret used for the original connection and thus be able to decrypt the\napplication data sent over that connection."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.21"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-4304","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-4304","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.21"],"available":[{"date":"2023-02-07","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-4304","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4304","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4304","date":"2026-10-08","epss":0.16195,"percentile":0.96865}],"risk":8.0975,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-4304"},"relatedVulnerabilities":[{"id":"CVE-2022-4304","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4304","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4304","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4304","date":"2026-10-08","epss":0.16195,"percentile":0.96865}],"urls":["https://security.gentoo.org/glsa/202402-08","https://www.openssl.org/news/secadv/20230207.txt","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-4304","description":"A timing based side channel exists in the OpenSSL RSA Decryption implementation\nwhich could be sufficient to recover a plaintext across a network in a\nBleichenbacher style attack. To achieve a successful decryption an attacker\nwould have to be able to send a very large number of trial messages for\ndecryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5,\nRSA-OEAP and RSASVE.\n\nFor example, in a TLS connection, RSA is commonly used by a client to send an\nencrypted pre-master secret to the server. An attacker that had observed a\ngenuine connection between a client and a server could use this flaw to send\ntrial messages to the server and record the time taken to process them. After a\nsufficiently large number of messages the attacker could recover the pre-master\nsecret used for the original connection and thus be able to decrypt the\napplication data sent over that connection."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.50"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9xcj-c8cr-8c3c","versionConstraint":">=8.0.0,<8.5.50 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-9xcj-c8cr-8c3c","fix":{"state":"fixed","versions":["8.5.50"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"8.5.50"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-17563","cwe":"CWE-384","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-17563","date":"2026-10-08","epss":0.10687,"percentile":0.95709}],"risk":8.01525,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-17563","https://lists.apache.org/thread.html/8b4c1db8300117b28a0f3f743c0b9e3f964687a690cdf9662a884bbd%40%3Cannounce.tomcat.apache.org%3E","https://seclists.org/bugtraq/2019/Dec/43","https://www.debian.org/security/2019/dsa-4596","https://security.netapp.com/advisory/ntap-20200107-0001/","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.html","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a@%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/01/msg00024.html","https://usn.ubuntu.com/4251-1/","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","https://security.gentoo.org/glsa/202003-43","https://www.debian.org/security/2020/dsa-4680","https://www.oracle.com/security-alerts/cpuapr2020.html","https://lists.apache.org/thread.html/reb9a66f176df29b9a832caa95ebd9ffa3284e8f4922ec4fa3ad8eb2e@%3Cissues.cxf.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9xcj-c8cr-8c3c","description":"In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack"},"relatedVulnerabilities":[{"id":"CVE-2019-17563","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"impactScore":6.5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-17563","cwe":"CWE-384","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-17563","date":"2026-10-08","epss":0.10687,"percentile":0.95709}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.html","https://lists.apache.org/thread.html/8b4c1db8300117b28a0f3f743c0b9e3f964687a690cdf9662a884bbd%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/reb9a66f176df29b9a832caa95ebd9ffa3284e8f4922ec4fa3ad8eb2e%40%3Cissues.cxf.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/01/msg00024.html","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","https://seclists.org/bugtraq/2019/Dec/43","https://security.gentoo.org/glsa/202003-43","https://security.netapp.com/advisory/ntap-20200107-0001/","https://usn.ubuntu.com/4251-1/","https://www.debian.org/security/2019/dsa-4596","https://www.debian.org/security/2020/dsa-4680","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-17563","description":"When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35559","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35559","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-35559","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-35559","date":"2026-10-08","epss":0.159,"percentile":0.96812}],"risk":7.95,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35559"},"relatedVulnerabilities":[{"id":"CVE-2021-35559","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-35559","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-35559","date":"2026-10-08","epss":0.159,"percentile":0.96812}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WTVCIVHTX3XONYOEGUMLKCM4QEC6INT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DJILEHYV2U37HKMGFEQ7CAVOV4DUWW2O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V362B2BWTH5IJDL45QPQGMBKIQOG7JX5/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-5000","https://www.debian.org/security/2021/dsa-5012","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35559","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.9.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gwp4-hfv6-p7hw","versionConstraint":">=2.9.0,<2.9.9.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gwp4-hfv6-p7hw","fix":{"state":"fixed","versions":["2.9.9.2"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.9.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14439","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14439","date":"2026-10-08","epss":0.10564,"percentile":0.95674}],"risk":7.922999999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-14439","https://github.com/FasterXML/jackson-databind/commit/ad418eeb974e357f2797aef64aa0e3ffaaa6125b","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2","https://github.com/FasterXML/jackson-databind/issues/2389","https://access.redhat.com/errata/RHSA-2019:3200","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef@%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/08/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20190814-0001/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gwp4-hfv6-p7hw","description":"Deserialization of untrusted data in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-14439","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14439","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14439","date":"2026-10-08","epss":0.10564,"percentile":0.95674}],"urls":["https://access.redhat.com/errata/RHSA-2019:3200","https://github.com/FasterXML/jackson-databind/commit/ad418eeb974e357f2797aef64aa0e3ffaaa6125b","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2","https://github.com/FasterXML/jackson-databind/issues/2389","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef%40%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/08/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20190814-0001/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-14439","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.9.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6fpp-rgj9-8rwc","versionConstraint":">=2.9.0,<2.9.9.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6fpp-rgj9-8rwc","fix":{"state":"fixed","versions":["2.9.9.2"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.9.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14379","cwe":"CWE-1321","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14379","date":"2026-10-08","epss":0.08111,"percentile":0.94695}],"risk":7.62434,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-14379","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2","https://github.com/FasterXML/jackson-databind/issues/2387","https://access.redhat.com/errata/RHBA-2019:2824","https://access.redhat.com/errata/RHSA-2019:2743","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:2998","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69@%3Ccommits.tinkerpop.apache.org%3E","https://lists.apache.org/thread.html/2766188be238a446a250ef76801037d452979152d85bce5e46805815@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/525bcf949a4b0da87a375cbad2680b8beccde749522f24c49befe7fb@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/689c6bcc6c7612eee71e453a115a4c8581e7b718537025d4b265783d@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/75f482fdc84abe6d0c8f438a76437c335a7bbeb5cddd4d70b4bc0cbf@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/859815b2e9f1575acbb2b260b73861c16ca49bca627fa0c46419051f@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/8723b52c2544e6cb804bc8a36622c584acd1bd6c53f2b6034c9fea54@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef@%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/99944f86abefde389da9b4040ea2327c6aa0b53a2ff9352bd4cfec17@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/d161ff3d59c5a8213400dd6afb1cce1fac4f687c32d1e0c0bfbfaa2d@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/e25e734c315f70d8876a846926cfe3bfa1a4888044f146e844caf72f@%3Ccommits.ambari.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/f17f63b0f8a57e4a5759e01d25cffc0548f0b61ff5c6bfd704ad2f2a@%3Ccommits.ambari.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/08/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC/","https://security.netapp.com/advisory/ntap-20190814-0001/","https://access.redhat.com/errata/RHSA-2019:3044","https://access.redhat.com/errata/RHSA-2019:3045","https://access.redhat.com/errata/RHSA-2019:3046","https://access.redhat.com/errata/RHSA-2019:3050","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2019:3292","https://access.redhat.com/errata/RHSA-2019:3297","https://access.redhat.com/errata/RHSA-2019:3901","https://access.redhat.com/errata/RHSA-2020:0727","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://support.apple.com/kb/HT213189","http://seclists.org/fulldisclosure/2022/Mar/23","https://github.com/FasterXML/jackson-databind/commit/ad418eeb974e357f2797aef64aa0e3ffaaa6125b"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6fpp-rgj9-8rwc","description":"Deserialization of untrusted data in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-14379","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14379","cwe":"CWE-1321","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14379","date":"2026-10-08","epss":0.08111,"percentile":0.94695}],"urls":["http://seclists.org/fulldisclosure/2022/Mar/23","https://access.redhat.com/errata/RHBA-2019:2824","https://access.redhat.com/errata/RHSA-2019:2743","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:2998","https://access.redhat.com/errata/RHSA-2019:3044","https://access.redhat.com/errata/RHSA-2019:3045","https://access.redhat.com/errata/RHSA-2019:3046","https://access.redhat.com/errata/RHSA-2019:3050","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2019:3292","https://access.redhat.com/errata/RHSA-2019:3297","https://access.redhat.com/errata/RHSA-2019:3901","https://access.redhat.com/errata/RHSA-2020:0727","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2","https://github.com/FasterXML/jackson-databind/issues/2387","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69%40%3Ccommits.tinkerpop.apache.org%3E","https://lists.apache.org/thread.html/2766188be238a446a250ef76801037d452979152d85bce5e46805815%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/525bcf949a4b0da87a375cbad2680b8beccde749522f24c49befe7fb%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/689c6bcc6c7612eee71e453a115a4c8581e7b718537025d4b265783d%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/75f482fdc84abe6d0c8f438a76437c335a7bbeb5cddd4d70b4bc0cbf%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/859815b2e9f1575acbb2b260b73861c16ca49bca627fa0c46419051f%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/8723b52c2544e6cb804bc8a36622c584acd1bd6c53f2b6034c9fea54%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef%40%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/99944f86abefde389da9b4040ea2327c6aa0b53a2ff9352bd4cfec17%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/d161ff3d59c5a8213400dd6afb1cce1fac4f687c32d1e0c0bfbfaa2d%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/e25e734c315f70d8876a846926cfe3bfa1a4888044f146e844caf72f%40%3Ccommits.ambari.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/f17f63b0f8a57e4a5759e01d25cffc0548f0b61ff5c6bfd704ad2f2a%40%3Ccommits.ambari.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/08/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC/","https://security.netapp.com/advisory/ntap-20190814-0001/","https://support.apple.com/kb/HT213189","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-14379","description":"SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution."}]},{"artifact":{"id":"3445236446ec4939","cpes":["cpe:2.3:a:krb5-locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5-locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"krb5-locales","purl":"pkg:deb/ubuntu/krb5-locales@1.16-2ubuntu0.1?arch=all&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/krb5-locales/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/krb5-locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/krb5-locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/krb5-locales.list"}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-3596","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-3596","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"risk":7.4295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-3596"},"relatedVulnerabilities":[{"id":"CVE-2024-3596","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/09/4","https://cert-portal.siemens.com/productcert/html/ssa-723487.html","https://cert-portal.siemens.com/productcert/html/ssa-794185.html","https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/","https://datatracker.ietf.org/doc/html/rfc2865","https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014","https://www.blastradius.fail/","https://security.netapp.com/advisory/ntap-20240822-0001/","https://today.ucsd.edu/story/computer-scientists-discover-vulnerabilities-in-a-popular-security-protocol","https://www.kb.cert.org/vuls/id/456537","https://cert-portal.siemens.com/productcert/html/ssa-364175.html","https://cert-portal.siemens.com/productcert/html/ssa-770770.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-3596","description":"RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature."}]},{"artifact":{"id":"f3fc35a2cb3401bd","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/ubuntu/libgssapi-krb5-2@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-3596","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-3596","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"risk":7.4295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-3596"},"relatedVulnerabilities":[{"id":"CVE-2024-3596","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/09/4","https://cert-portal.siemens.com/productcert/html/ssa-723487.html","https://cert-portal.siemens.com/productcert/html/ssa-794185.html","https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/","https://datatracker.ietf.org/doc/html/rfc2865","https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014","https://www.blastradius.fail/","https://security.netapp.com/advisory/ntap-20240822-0001/","https://today.ucsd.edu/story/computer-scientists-discover-vulnerabilities-in-a-popular-security-protocol","https://www.kb.cert.org/vuls/id/456537","https://cert-portal.siemens.com/productcert/html/ssa-364175.html","https://cert-portal.siemens.com/productcert/html/ssa-770770.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-3596","description":"RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature."}]},{"artifact":{"id":"ce64c2275844a0e2","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/ubuntu/libk5crypto3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-3596","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-3596","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"risk":7.4295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-3596"},"relatedVulnerabilities":[{"id":"CVE-2024-3596","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/09/4","https://cert-portal.siemens.com/productcert/html/ssa-723487.html","https://cert-portal.siemens.com/productcert/html/ssa-794185.html","https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/","https://datatracker.ietf.org/doc/html/rfc2865","https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014","https://www.blastradius.fail/","https://security.netapp.com/advisory/ntap-20240822-0001/","https://today.ucsd.edu/story/computer-scientists-discover-vulnerabilities-in-a-popular-security-protocol","https://www.kb.cert.org/vuls/id/456537","https://cert-portal.siemens.com/productcert/html/ssa-364175.html","https://cert-portal.siemens.com/productcert/html/ssa-770770.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-3596","description":"RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature."}]},{"artifact":{"id":"a0e77fe46f00e692","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/ubuntu/libkrb5-3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-3596","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-3596","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"risk":7.4295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-3596"},"relatedVulnerabilities":[{"id":"CVE-2024-3596","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/09/4","https://cert-portal.siemens.com/productcert/html/ssa-723487.html","https://cert-portal.siemens.com/productcert/html/ssa-794185.html","https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/","https://datatracker.ietf.org/doc/html/rfc2865","https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014","https://www.blastradius.fail/","https://security.netapp.com/advisory/ntap-20240822-0001/","https://today.ucsd.edu/story/computer-scientists-discover-vulnerabilities-in-a-popular-security-protocol","https://www.kb.cert.org/vuls/id/456537","https://cert-portal.siemens.com/productcert/html/ssa-364175.html","https://cert-portal.siemens.com/productcert/html/ssa-770770.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-3596","description":"RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature."}]},{"artifact":{"id":"402827dd4cb6593f","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/ubuntu/libkrb5support0@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-3596","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-3596","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"risk":7.4295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-3596"},"relatedVulnerabilities":[{"id":"CVE-2024-3596","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/09/4","https://cert-portal.siemens.com/productcert/html/ssa-723487.html","https://cert-portal.siemens.com/productcert/html/ssa-794185.html","https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/","https://datatracker.ietf.org/doc/html/rfc2865","https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014","https://www.blastradius.fail/","https://security.netapp.com/advisory/ntap-20240822-0001/","https://today.ucsd.edu/story/computer-scientists-discover-vulnerabilities-in-a-popular-security-protocol","https://www.kb.cert.org/vuls/id/456537","https://cert-portal.siemens.com/productcert/html/ssa-364175.html","https://cert-portal.siemens.com/productcert/html/ssa-770770.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-3596","description":"RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.64"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f4qf-m5gf-8jm8","versionConstraint":">=8.5.7,<8.5.64 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-f4qf-m5gf-8jm8","fix":{"state":"fixed","versions":["8.5.64"],"available":[{"date":"2024-04-24","kind":"first-observed","version":"8.5.64"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-21733","cwe":"CWE-209","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-21733","date":"2026-10-08","epss":0.14286,"percentile":0.9652}],"risk":7.35729,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-21733","https://lists.apache.org/thread/h9bjqdd0odj6lhs2o96qgowcc6hb0cfz","http://www.openwall.com/lists/oss-security/2024/01/19/2","http://packetstormsecurity.com/files/176951/Apache-Tomcat-8.5.63-9.0.43-HTTP-Response-Smuggling.html","https://security.netapp.com/advisory/ntap-20240216-0005","https://github.com/apache/tomcat/commit/86ccc43940861703c2be96a5f35384407522125a","https://github.com/apache/tomcat/commit/ce4b154e7b48f66bd98858626347747cd2514311","https://tomcat.apache.org/security-8.html","https://tomcat.apache.org/security-9.html","https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f4qf-m5gf-8jm8","description":"Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information"},"relatedVulnerabilities":[{"id":"CVE-2024-21733","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-21733","cwe":"CWE-209","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-21733","date":"2026-10-08","epss":0.14286,"percentile":0.9652}],"urls":["https://lists.apache.org/thread/h9bjqdd0odj6lhs2o96qgowcc6hb0cfz","http://packetstormsecurity.com/files/176951/Apache-Tomcat-8.5.63-9.0.43-HTTP-Response-Smuggling.html","http://www.openwall.com/lists/oss-security/2024/01/19/2","https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html","https://security.netapp.com/advisory/ntap-20240216-0005/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-21733","description":"Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL versions may also be affected.\n\nUsers are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x2w5-5m2g-7h5m","versionConstraint":">=2.9.0,<2.9.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-x2w5-5m2g-7h5m","fix":{"state":"fixed","versions":["2.9.7"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-14720","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-14720","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-14720","date":"2026-10-08","epss":0.07524,"percentile":0.94351}],"risk":7.07256,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-14720","https://github.com/FasterXML/jackson-databind/issues/2097","https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:1106","https://access.redhat.com/errata/RHSA-2019:1107","https://access.redhat.com/errata/RHSA-2019:1108","https://access.redhat.com/errata/RHSA-2019:1140","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/6a78f88716c3c57aa74ec05764a37ab3874769a347805903b393b286@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/82b01bfb6787097427ce97cec6a7127e93718bc05d1efd5eaffc228f@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/ba973114605d936be276ee6ce09dfbdbf78aa56f6cdc6e79bfa7b8df@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x2w5-5m2g-7h5m","description":"XML External Entity Reference (XXE) in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2018-14720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-14720","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-14720","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-14720","date":"2026-10-08","epss":0.07524,"percentile":0.94351}],"urls":["https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:1106","https://access.redhat.com/errata/RHSA-2019:1107","https://access.redhat.com/errata/RHSA-2019:1108","https://access.redhat.com/errata/RHSA-2019:1140","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44","https://github.com/FasterXML/jackson-databind/issues/2097","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/6a78f88716c3c57aa74ec05764a37ab3874769a347805903b393b286%40%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/82b01bfb6787097427ce97cec6a7127e93718bc05d1efd5eaffc228f%40%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/ba973114605d936be276ee6ce09dfbdbf78aa56f6cdc6e79bfa7b8df%40%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-14720","description":"FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization."}]},{"artifact":{"id":"e9c085cc914ff4cd","cpes":["cpe:2.3:a:springsource-spring-framework:springsource_spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource_spring_framework:springsource_spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:springsource_spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource-spring:springsource_spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource_spring:springsource_spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:springsource_spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-framework:springsource_spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_framework:springsource_spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource-spring-framework:spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource_spring_framework:spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:springsource_spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource:springsource_spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-core:springsource_spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_core:springsource_spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource-spring-framework:spring-core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource-spring-framework:spring_core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource_spring_framework:spring-core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource_spring_framework:spring_core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:springsource_spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource-spring:spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource_spring:spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:springsource_spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-framework:spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_framework:spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring-core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource-spring:spring-core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource-spring:spring_core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource_spring:spring-core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource_spring:spring_core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource:spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:spring-core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:spring_core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-core:spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-framework:spring-core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-framework:spring_core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_core:spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_framework:spring-core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_framework:spring_core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource:spring-core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springsource:spring_core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-core:spring-core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-core:spring_core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_core:spring-core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_core:spring_core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring-core:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_core:5.0.8.RELEASE:*:*:*:*:*:*:*"],"name":"spring-core","purl":"pkg:maven/org.springframework/spring-core@5.0.8.RELEASE","type":"java-archive","version":"5.0.8.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-core-5.0.8.RELEASE.jar","manifestName":"","pomArtifactID":"spring-core","archiveDigests":[{"value":"dc39c49e3246cdf73d3786ac41119140aed3fa08","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-core-5.0.8.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.0.10.RELEASE"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-ffvq-7w96-97p7","versionConstraint":">=5.0.0.RELEASE,<5.0.10.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-core","version":"5.0.8.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-ffvq-7w96-97p7","fix":{"state":"fixed","versions":["5.0.10.RELEASE"],"available":[{"date":"2024-06-06","kind":"first-observed","version":"5.0.10.RELEASE"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-15756","date":"2026-10-08","epss":0.09207,"percentile":0.95222}],"risk":6.9052500000000006,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-15756","https://lists.apache.org/thread.html/339fd112517e4873695b5115b96acdddbfc8f83b10598528d37c7d12@%3Cissues.activemq.apache.org%3E","https://pivotal.io/security/cve-2018-15756","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","http://www.securityfocus.com/bid/105703","https://lists.apache.org/thread.html/77886fec378ee6064debb1efb6b464a4a0173b2ff0d151ed86d3a228@%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/7b156ee50ba3ecce87b33c06bf7a749d84ffee55e69bfb5eca88fcc3@%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/8a1fe70534fc52ff5c9db5ac29c55657f802cbefd7e9d9850c7052bd@%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/a3071e11c6fbd593022074ec1b4693f6d948c2b02cfa4a5d854aed68@%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/bb354962cb51fff65740d5fb1bc2aac56af577c06244b57c36f98e4d@%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/d6a84f52db89804b0ad965f3ea2b24bb880edee29107a1c5069cc3dd@%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/efaa52b0aa67aae7cbd9e6ef96945387e422d7ce0e65434570a37b1d@%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/f8905507a2c94af6b08b72d7be0c4b8c6660e585f00abfafeccc86bc@%3Cissues.activemq.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-ffvq-7w96-97p7","description":"Denial of Service in Spring Framework"},"relatedVulnerabilities":[{"id":"CVE-2018-15756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security_alert@emc.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-15756","date":"2026-10-08","epss":0.09207,"percentile":0.95222}],"urls":["http://www.securityfocus.com/bid/105703","https://lists.apache.org/thread.html/339fd112517e4873695b5115b96acdddbfc8f83b10598528d37c7d12%40%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/77886fec378ee6064debb1efb6b464a4a0173b2ff0d151ed86d3a228%40%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/7b156ee50ba3ecce87b33c06bf7a749d84ffee55e69bfb5eca88fcc3%40%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/8a1fe70534fc52ff5c9db5ac29c55657f802cbefd7e9d9850c7052bd%40%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/a3071e11c6fbd593022074ec1b4693f6d948c2b02cfa4a5d854aed68%40%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/bb354962cb51fff65740d5fb1bc2aac56af577c06244b57c36f98e4d%40%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/d6a84f52db89804b0ad965f3ea2b24bb880edee29107a1c5069cc3dd%40%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/efaa52b0aa67aae7cbd9e6ef96945387e422d7ce0e65434570a37b1d%40%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/f8905507a2c94af6b08b72d7be0c4b8c6660e585f00abfafeccc86bc%40%3Cissues.activemq.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html","https://pivotal.io/security/cve-2018-15756","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15756","description":"Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack. This vulnerability affects applications that depend on either spring-webmvc or spring-webflux. Such applications must also have a registration for serving static resources (e.g. JS, CSS, images, and others), or have an annotated controller that returns an org.springframework.core.io.Resource. Spring Boot applications that depend on spring-boot-starter-web or spring-boot-starter-webflux are ready to serve static resources out of the box and are therefore vulnerable."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.61"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jgwr-3qm3-26f3","versionConstraint":">=8.0.0,<8.5.61 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-jgwr-3qm3-26f3","fix":{"state":"fixed","versions":["8.5.61"],"available":[{"date":"2021-03-20","kind":"first-observed","version":"8.5.61"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-25329","date":"2026-10-08","epss":0.09491,"percentile":0.95325}],"risk":6.8809749999999985,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-25329","https://github.com/apache/tomcat/commit/6d66e99ef85da93e4d2c2a536ca51aa3418bfaf4","https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cusers.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/03/msg00018.html","http://www.openwall.com/lists/oss-security/2021/03/01/2","https://security.netapp.com/advisory/ntap-20210409-0002/","https://www.debian.org/security/2021/dsa-4891","https://lists.apache.org/thread.html/r732b2ca289dc02df2de820e8775559abd6c207f159e39f559547a085@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77@%3Cusers.tomcat.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://security.gentoo.org/glsa/202208-34"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jgwr-3qm3-26f3","description":"Potential remote code execution in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2021-25329","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.4,"impactScore":6.5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-25329","date":"2026-10-08","epss":0.09491,"percentile":0.95325}],"urls":["http://www.openwall.com/lists/oss-security/2021/03/01/2","https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r732b2ca289dc02df2de820e8775559abd6c207f159e39f559547a085%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cusers.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/03/msg00018.html","https://security.gentoo.org/glsa/202208-34","https://security.netapp.com/advisory/ntap-20210409-0002/","https://www.debian.org/security/2021/dsa-4891","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-25329","description":"The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f9xh-2qgp-cq57","versionConstraint":">=2.7.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-f9xh-2qgp-cq57","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36188","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36188","date":"2026-10-08","epss":0.08787,"percentile":0.95056}],"risk":6.853860000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36188","https://github.com/FasterXML/jackson-databind/issues/2996","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/33d96c13fe18a2dad01b19ce195548c9acea9da4"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f9xh-2qgp-cq57","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36188","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36188","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36188","date":"2026-10-08","epss":0.08787,"percentile":0.95056}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/2996","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36188","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource."}]},{"artifact":{"id":"116ba9b4dedae730","cpes":["cpe:2.3:a:metastuff-ltd-:dom4j:1.6.1:*:*:*:*:*:*:*","cpe:2.3:a:metastuff_ltd_:dom4j:1.6.1:*:*:*:*:*:*:*","cpe:2.3:a:org.dom4j:dom4j:1.6.1:*:*:*:*:*:*:*","cpe:2.3:a:dom4j:dom4j:1.6.1:*:*:*:*:*:*:*"],"name":"dom4j","purl":"pkg:maven/org.dom4j/dom4j@1.6.1","type":"java-archive","version":"1.6.1","language":"java","licenses":["sha256:9a6b4e9e1668b2cc31453527ee07a1a68495f4cae149cfe03a8c955e6093ec55"],"metadata":{"pomGroupID":"org.dom4j","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/dom4j-1.6.1.jar","manifestName":"","pomArtifactID":"dom4j","archiveDigests":[{"value":"5d3ccc056b6f056dbf0dddfdf43894b9065a8f94","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/dom4j-1.6.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.0.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hwj3-m3p6-hj38","versionConstraint":"<2.0.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.dom4j:dom4j","version":"1.6.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hwj3-m3p6-hj38","fix":{"state":"fixed","versions":["2.0.3"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.0.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10683","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10683","date":"2026-10-08","epss":0.07269,"percentile":0.94202}],"risk":6.83286,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-10683","https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658","https://bugzilla.redhat.com/show_bug.cgi?id=1694235","https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html","https://github.com/dom4j/dom4j/releases/tag/version-2.1.3","https://security.netapp.com/advisory/ntap-20200518-0002/","http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.html","https://github.com/dom4j/dom4j/commit/1707bf3d898a8ada3b213acb0e3b38f16eaae73d","https://www.oracle.com/security-alerts/cpujul2020.html","https://github.com/dom4j/dom4j/issues/87","https://github.com/dom4j/dom4j/commits/version-2.0.3","https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8@%3Cdev.velocity.apache.org%3E","https://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32@%3Cdev.velocity.apache.org%3E","https://usn.ubuntu.com/4575-1/","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51@%3Cnotifications.freemarker.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hwj3-m3p6-hj38","description":"dom4j allows External Entities by default which might enable XXE attacks"},"relatedVulnerabilities":[{"id":"CVE-2020-10683","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10683","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10683","date":"2026-10-08","epss":0.07269,"percentile":0.94202}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.html","https://bugzilla.redhat.com/show_bug.cgi?id=1694235","https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html","https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658","https://github.com/dom4j/dom4j/commits/version-2.0.3","https://github.com/dom4j/dom4j/issues/87","https://github.com/dom4j/dom4j/releases/tag/version-2.1.3","https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8%40%3Cdev.velocity.apache.org%3E","https://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32%40%3Cdev.velocity.apache.org%3E","https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51%40%3Cnotifications.freemarker.apache.org%3E","https://security.netapp.com/advisory/ntap-20200518-0002/","https://usn.ubuntu.com/4575-1/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10683","description":"dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j823-4qch-3rgm","versionConstraint":">=2.9.0,<=2.9.10.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j823-4qch-3rgm","fix":{"state":"fixed","versions":["2.9.10.5"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14060","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14060","date":"2026-10-08","epss":0.08607,"percentile":0.94968}],"risk":6.71346,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-14060","https://github.com/FasterXML/jackson-databind/issues/2688","https://github.com/FasterXML/jackson-databind/commit/d1c67a0396e84c08d0558fbb843b5bd1f26e1921","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://github.com/FasterXML/jackson-databind/commit/ac7232e3f9004bdb4f11dcb5bc6c1fadf074f5f7","https://security.netapp.com/advisory/ntap-20200702-0003","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j823-4qch-3rgm","description":"Deserialization of untrusted data in Jackson Databind"},"relatedVulnerabilities":[{"id":"CVE-2020-14060","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14060","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14060","date":"2026-10-08","epss":0.08607,"percentile":0.94968}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2688","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200702-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14060","description":"FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill)."}]},{"artifact":{"id":"6626581ee00a1e60","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:237-3ubuntu10.11:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@237-3ubuntu10.11?arch=amd64&distro=ubuntu-18.04&upstream=systemd","type":"deb","version":"237-3ubuntu10.11","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"237-3ubuntu10.49"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-33910","versionConstraint":"< 237-3ubuntu10.49 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"systemd","version":"237-3ubuntu10.11"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-33910","fix":{"state":"fixed","versions":["237-3ubuntu10.49"],"available":[{"date":"2021-07-20","kind":"advisory","version":"237-3ubuntu10.49"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33910","date":"2026-10-08","epss":0.08792,"percentile":0.95058}],"risk":6.593999999999999,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-33910"},"relatedVulnerabilities":[{"id":"CVE-2021-33910","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33910","date":"2026-10-08","epss":0.08792,"percentile":0.95058}],"urls":["http://packetstormsecurity.com/files/163621/Sequoia-A-Deep-Root-In-Linuxs-Filesystem-Layer.html","http://www.openwall.com/lists/oss-security/2021/08/04/2","http://www.openwall.com/lists/oss-security/2021/08/17/3","http://www.openwall.com/lists/oss-security/2021/09/07/3","https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf","https://github.com/systemd/systemd-stable/commit/4a1c5f34bd3e1daed4490e9d97918e504d19733b","https://github.com/systemd/systemd-stable/commit/764b74113e36ac5219a4b82a05f311b5a92136ce","https://github.com/systemd/systemd-stable/commit/b00674347337b7531c92fdb65590ab253bb57538","https://github.com/systemd/systemd-stable/commit/cfd14c65374027b34dbbc4f0551456c5dc2d1f61","https://github.com/systemd/systemd/commit/b34a4f0e6729de292cb3b0c03c1d48f246ad896b","https://github.com/systemd/systemd/pull/20256/commits/441e0115646d54f080e5c3bb0ba477c892861ab9","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/","https://security.gentoo.org/glsa/202107-48","https://security.netapp.com/advisory/ntap-20211104-0008/","https://www.debian.org/security/2021/dsa-4942","https://www.openwall.com/lists/oss-security/2021/07/20/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-33910","description":"basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash."}]},{"artifact":{"id":"dee40f7c61cf4f45","cpes":["cpe:2.3:a:libudev1:libudev1:237-3ubuntu10.11:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@237-3ubuntu10.11?arch=amd64&distro=ubuntu-18.04&upstream=systemd","type":"deb","version":"237-3ubuntu10.11","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"237-3ubuntu10.49"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-33910","versionConstraint":"< 237-3ubuntu10.49 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"systemd","version":"237-3ubuntu10.11"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-33910","fix":{"state":"fixed","versions":["237-3ubuntu10.49"],"available":[{"date":"2021-07-20","kind":"advisory","version":"237-3ubuntu10.49"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33910","date":"2026-10-08","epss":0.08792,"percentile":0.95058}],"risk":6.593999999999999,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-33910"},"relatedVulnerabilities":[{"id":"CVE-2021-33910","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33910","date":"2026-10-08","epss":0.08792,"percentile":0.95058}],"urls":["http://packetstormsecurity.com/files/163621/Sequoia-A-Deep-Root-In-Linuxs-Filesystem-Layer.html","http://www.openwall.com/lists/oss-security/2021/08/04/2","http://www.openwall.com/lists/oss-security/2021/08/17/3","http://www.openwall.com/lists/oss-security/2021/09/07/3","https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf","https://github.com/systemd/systemd-stable/commit/4a1c5f34bd3e1daed4490e9d97918e504d19733b","https://github.com/systemd/systemd-stable/commit/764b74113e36ac5219a4b82a05f311b5a92136ce","https://github.com/systemd/systemd-stable/commit/b00674347337b7531c92fdb65590ab253bb57538","https://github.com/systemd/systemd-stable/commit/cfd14c65374027b34dbbc4f0551456c5dc2d1f61","https://github.com/systemd/systemd/commit/b34a4f0e6729de292cb3b0c03c1d48f246ad896b","https://github.com/systemd/systemd/pull/20256/commits/441e0115646d54f080e5c3bb0ba477c892861ab9","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/","https://security.gentoo.org/glsa/202107-48","https://security.netapp.com/advisory/ntap-20211104-0008/","https://www.debian.org/security/2021/dsa-4942","https://www.openwall.com/lists/oss-security/2021/07/20/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-33910","description":"basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-fqwf-pjwf-7vqv","versionConstraint":">=2.7.0,<2.9.10.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-fqwf-pjwf-7vqv","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10673","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10673","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10673","date":"2026-10-08","epss":0.08028,"percentile":0.94643}],"risk":6.542820000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-10673","https://github.com/FasterXML/jackson-databind/issues/2660","https://lists.debian.org/debian-lts-announce/2020/03/msg00027.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/1645efbd392989cf015f459a91c999e59c921b15","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-fqwf-pjwf-7vqv","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-10673","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10673","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10673","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10673","date":"2026-10-08","epss":0.08028,"percentile":0.94643}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2660","https://lists.debian.org/debian-lts-announce/2020/03/msg00027.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10673","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus)."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m6x4-97wx-4q27","versionConstraint":">=2.0.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-m6x4-97wx-4q27","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36184","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36184","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36184","date":"2026-10-08","epss":0.08356,"percentile":0.94829}],"risk":6.5176799999999995,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36184","https://github.com/FasterXML/jackson-databind/issues/2998","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/567194c53ae91f0a14dc27239afb739b1c10448a"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m6x4-97wx-4q27","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36184","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36184","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36184","date":"2026-10-08","epss":0.08356,"percentile":0.94829}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/2998","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36184","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-3822","versionConstraint":"< 7.58.0-2ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-3822","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.6"],"available":[{"date":"2019-02-06","kind":"advisory","version":"7.58.0-2ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-3822","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-3822","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-3822","date":"2026-10-08","epss":0.12873,"percentile":0.96213}],"risk":6.4365000000000006,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-3822"},"relatedVulnerabilities":[{"id":"CVE-2019-3822","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-3822","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-3822","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-3822","date":"2026-10-08","epss":0.12873,"percentile":0.96213}],"urls":["http://www.securityfocus.com/bid/106950","https://access.redhat.com/errata/RHSA-2019:3701","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3822","https://cert-portal.siemens.com/productcert/pdf/ssa-436177.pdf","https://curl.haxx.se/docs/CVE-2019-3822.html","https://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3E","https://security.gentoo.org/glsa/201903-03","https://security.netapp.com/advisory/ntap-20190315-0001/","https://security.netapp.com/advisory/ntap-20190719-0004/","https://support.f5.com/csp/article/K84141449","https://support.f5.com/csp/article/K84141449?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/3882-1/","https://www.debian.org/security/2019/dsa-4386","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-3822","description":"libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent the local buffer from getting overflowed is implemented wrongly (using unsigned math) and as such it does not prevent the overflow from happening. This output data can grow larger than the local buffer if very large 'nt response' data is extracted from a previous NTLMv2 header provided by the malicious or broken HTTP server. Such a 'large value' needs to be around 1000 bytes or more. The actual payload data copied to the target buffer comes from the NTLMv2 type-2 response header."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-3822","versionConstraint":"< 7.58.0-2ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-3822","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.6"],"available":[{"date":"2019-02-06","kind":"advisory","version":"7.58.0-2ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-3822","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-3822","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-3822","date":"2026-10-08","epss":0.12873,"percentile":0.96213}],"risk":6.4365000000000006,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-3822"},"relatedVulnerabilities":[{"id":"CVE-2019-3822","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-3822","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-3822","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-3822","date":"2026-10-08","epss":0.12873,"percentile":0.96213}],"urls":["http://www.securityfocus.com/bid/106950","https://access.redhat.com/errata/RHSA-2019:3701","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3822","https://cert-portal.siemens.com/productcert/pdf/ssa-436177.pdf","https://curl.haxx.se/docs/CVE-2019-3822.html","https://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3E","https://security.gentoo.org/glsa/201903-03","https://security.netapp.com/advisory/ntap-20190315-0001/","https://security.netapp.com/advisory/ntap-20190719-0004/","https://support.f5.com/csp/article/K84141449","https://support.f5.com/csp/article/K84141449?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/3882-1/","https://www.debian.org/security/2019/dsa-4386","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-3822","description":"libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent the local buffer from getting overflowed is implemented wrongly (using unsigned math) and as such it does not prevent the overflow from happening. This output data can grow larger than the local buffer if very large 'nt response' data is extracted from a previous NTLMv2 header provided by the malicious or broken HTTP server. Such a 'large value' needs to be around 1000 bytes or more. The actual payload data copied to the target buffer comes from the NTLMv2 type-2 response header."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c265-37vj-cwcc","versionConstraint":">=2.9.0,<=2.9.10.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c265-37vj-cwcc","fix":{"state":"fixed","versions":["2.9.10.5"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14062","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14062","date":"2026-10-08","epss":0.08108,"percentile":0.94694}],"risk":6.3242400000000005,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-14062","https://github.com/FasterXML/jackson-databind/issues/2704","https://github.com/FasterXML/jackson-databind/commit/99001cdb6807b5c7b170ec6a9092ecbb618ae79c","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/840eae2ca81c597a0010b2126f32dce17d384b70","https://security.netapp.com/advisory/ntap-20200702-0003","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c265-37vj-cwcc","description":"Deserialization of untrusted data in Jackson Databind"},"relatedVulnerabilities":[{"id":"CVE-2020-14062","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14062","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14062","date":"2026-10-08","epss":0.08108,"percentile":0.94694}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2704","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200702-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14062","description":"FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2)."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-5010","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-5010","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5010","cwe":"CWE-476","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5010","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5010","date":"2026-10-08","epss":0.20743,"percentile":0.97484}],"risk":6.2229,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5010"},"relatedVulnerabilities":[{"id":"CVE-2019-5010","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5010","cwe":"CWE-476","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5010","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5010","date":"2026-10-08","epss":0.20743,"percentile":0.97484}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","https://access.redhat.com/errata/RHSA-2019:3520","https://access.redhat.com/errata/RHSA-2019:3725","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://security.gentoo.org/glsa/202003-26","https://talosintelligence.com/vulnerability_reports/TALOS-2019-0758"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5010","description":"An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-5010","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-5010","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5010","cwe":"CWE-476","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5010","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5010","date":"2026-10-08","epss":0.20743,"percentile":0.97484}],"risk":6.2229,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5010"},"relatedVulnerabilities":[{"id":"CVE-2019-5010","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5010","cwe":"CWE-476","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5010","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5010","date":"2026-10-08","epss":0.20743,"percentile":0.97484}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","https://access.redhat.com/errata/RHSA-2019:3520","https://access.redhat.com/errata/RHSA-2019:3725","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://security.gentoo.org/glsa/202003-26","https://talosintelligence.com/vulnerability_reports/TALOS-2019-0758"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5010","description":"An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-5010","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-5010","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5010","cwe":"CWE-476","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5010","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5010","date":"2026-10-08","epss":0.20743,"percentile":0.97484}],"risk":6.2229,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5010"},"relatedVulnerabilities":[{"id":"CVE-2019-5010","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5010","cwe":"CWE-476","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5010","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5010","date":"2026-10-08","epss":0.20743,"percentile":0.97484}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","https://access.redhat.com/errata/RHSA-2019:3520","https://access.redhat.com/errata/RHSA-2019:3725","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://security.gentoo.org/glsa/202003-26","https://talosintelligence.com/vulnerability_reports/TALOS-2019-0758"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5010","description":"An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-5010","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-5010","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5010","cwe":"CWE-476","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5010","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5010","date":"2026-10-08","epss":0.20743,"percentile":0.97484}],"risk":6.2229,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5010"},"relatedVulnerabilities":[{"id":"CVE-2019-5010","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5010","cwe":"CWE-476","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5010","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5010","date":"2026-10-08","epss":0.20743,"percentile":0.97484}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","https://access.redhat.com/errata/RHSA-2019:3520","https://access.redhat.com/errata/RHSA-2019:3725","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://security.gentoo.org/glsa/202003-26","https://talosintelligence.com/vulnerability_reports/TALOS-2019-0758"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5010","description":"An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r3gr-cxrf-hg25","versionConstraint":">=2.0.0,<=2.9.10.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r3gr-cxrf-hg25","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-35491","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-35491","date":"2026-10-08","epss":0.0775,"percentile":0.94492}],"risk":6.045,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-35491","https://github.com/FasterXML/jackson-databind/issues/2986","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/41b8bdb5ccc1d8edb71acf1c8234da235a24249d","https://security.netapp.com/advisory/ntap-20210122-0005"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r3gr-cxrf-hg25","description":"Serialization gadgets exploit in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-35491","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-35491","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-35491","date":"2026-10-08","epss":0.0775,"percentile":0.94492}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/2986","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210122-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-35491","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource."}]},{"artifact":{"id":"0c17bed56057f9e7","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.1?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36230","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36230","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36230","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36230","date":"2026-10-08","epss":0.11968,"percentile":0.96027}],"risk":5.984,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36230"},"relatedVulnerabilities":[{"id":"CVE-2020-36230","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36230","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36230","date":"2026-10-08","epss":0.11968,"percentile":0.96027}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9423","https://git.openldap.org/openldap/openldap/-/commit/8c1d96ee36ed98b32cd0e28b7069c7b8ea09d793","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36230","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service."}]},{"artifact":{"id":"d1ea226d64532803","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.1?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36230","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36230","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36230","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36230","date":"2026-10-08","epss":0.11968,"percentile":0.96027}],"risk":5.984,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36230"},"relatedVulnerabilities":[{"id":"CVE-2020-36230","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36230","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36230","date":"2026-10-08","epss":0.11968,"percentile":0.96027}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9423","https://git.openldap.org/openldap/openldap/-/commit/8c1d96ee36ed98b32cd0e28b7069c7b8ea09d793","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36230","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.9.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cmfg-87vq-g5g4","versionConstraint":">=2.9.0,<2.9.9.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cmfg-87vq-g5g4","fix":{"state":"fixed","versions":["2.9.9.1"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.9.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12814","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-12814","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-12814","date":"2026-10-08","epss":0.10902,"percentile":0.95774}],"risk":5.941590000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-12814","https://github.com/FasterXML/jackson-databind/issues/2341","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:3044","https://access.redhat.com/errata/RHSA-2019:3045","https://access.redhat.com/errata/RHSA-2019:3046","https://access.redhat.com/errata/RHSA-2019:3050","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2019:3292","https://access.redhat.com/errata/RHSA-2019:3297","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/129da0204c876f746636018751a086cc581e0e07bcdeb3ee22ff5731@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/15a55e1d837fa686db493137cc0330c7ee1089ed9a9eea7ae7151ef1@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/1e04d9381c801b31ab28dec813c31c304b2a596b2a3707fa5462c5c0@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/28be28ffd6471d230943a255c36fe196a54ef5afc494a4781d16e37c@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/2ff264b6a94c5363a35c4c88fa93216f60ec54d1d973ed6b76a9f560@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/4b832d1327703d6b287a6d223307f8f884d798821209a10647e93324@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/71f9ffd92410a889e27b95a219eaa843fd820f8550898633d85d4ea3@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/8fe2983f6d9fee0aa737e4bd24483f8f5cf9b938b9adad0c4e79b2a4@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef@%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/a3ae8a8c5e32c413cd27071d3a204166050bf79ce7f1299f6866338f@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/a62aa2706105d68f1c02023fe24aaa3c13b4d8a1826181fed07d9682@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/a78239b1f11cddfa86e4edee19064c40b6272214630bfef070c37957@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0a2b2cca072650dbd5882719976c3d353972c44f6736ddf0ba95209@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/b148fa2e9ef468c4de00de255dd728b74e2a97d935f8ced31eb41ba2@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/bf20574dbc2db255f1fd489942b5720f675e32a2c4f44eb6a36060cd@%3Ccommits.accumulo.apache.org%3E","https://lists.apache.org/thread.html/e0733058c0366b703e6757d8d2a7a04b943581f659e9c271f0841dfe@%3Cnotifications.geode.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/eff7280055fc717ea8129cd28a9dd57b8446d00b36260c1caee10b87@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00019.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/5f7c69bba07a7155adde130d9dee2e54a54f1fa5","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC","https://security.netapp.com/advisory/ntap-20190625-0006"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cmfg-87vq-g5g4","description":"Deserialization of untrusted data in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-12814","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12814","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-12814","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-12814","date":"2026-10-08","epss":0.10902,"percentile":0.95774}],"urls":["https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:3044","https://access.redhat.com/errata/RHSA-2019:3045","https://access.redhat.com/errata/RHSA-2019:3046","https://access.redhat.com/errata/RHSA-2019:3050","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2019:3292","https://access.redhat.com/errata/RHSA-2019:3297","https://github.com/FasterXML/jackson-databind/issues/2341","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/129da0204c876f746636018751a086cc581e0e07bcdeb3ee22ff5731%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/15a55e1d837fa686db493137cc0330c7ee1089ed9a9eea7ae7151ef1%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/1e04d9381c801b31ab28dec813c31c304b2a596b2a3707fa5462c5c0%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/28be28ffd6471d230943a255c36fe196a54ef5afc494a4781d16e37c%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/2ff264b6a94c5363a35c4c88fa93216f60ec54d1d973ed6b76a9f560%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/4b832d1327703d6b287a6d223307f8f884d798821209a10647e93324%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/71f9ffd92410a889e27b95a219eaa843fd820f8550898633d85d4ea3%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/8fe2983f6d9fee0aa737e4bd24483f8f5cf9b938b9adad0c4e79b2a4%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef%40%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/a3ae8a8c5e32c413cd27071d3a204166050bf79ce7f1299f6866338f%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/a62aa2706105d68f1c02023fe24aaa3c13b4d8a1826181fed07d9682%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/a78239b1f11cddfa86e4edee19064c40b6272214630bfef070c37957%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0a2b2cca072650dbd5882719976c3d353972c44f6736ddf0ba95209%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/b148fa2e9ef468c4de00de255dd728b74e2a97d935f8ced31eb41ba2%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/bf20574dbc2db255f1fd489942b5720f675e32a2c4f44eb6a36060cd%40%3Ccommits.accumulo.apache.org%3E","https://lists.apache.org/thread.html/e0733058c0366b703e6757d8d2a7a04b943581f659e9c271f0841dfe%40%3Cnotifications.geode.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/eff7280055fc717ea8129cd28a9dd57b8446d00b36260c1caee10b87%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC/","https://security.netapp.com/advisory/ntap-20190625-0006/","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12814","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9948","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9948","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9948","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9948","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9948","date":"2026-10-08","epss":0.11844,"percentile":0.95998}],"risk":5.922000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9948"},"relatedVulnerabilities":[{"id":"CVE-2019-9948","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9948","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9948","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9948","date":"2026-10-08","epss":0.11844,"percentile":0.95998}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.html","http://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python-Updates.html","http://www.securityfocus.com/bid/107549","https://access.redhat.com/errata/RHSA-2019:1700","https://access.redhat.com/errata/RHSA-2019:2030","https://access.redhat.com/errata/RHSA-2019:3335","https://access.redhat.com/errata/RHSA-2019:3520","https://bugs.python.org/issue35907","https://github.com/python/cpython/pull/11842","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/","https://seclists.org/bugtraq/2019/Oct/29","https://security.gentoo.org/glsa/202003-26","https://security.netapp.com/advisory/ntap-20190404-0004/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9948","description":"urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9948","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9948","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9948","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9948","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9948","date":"2026-10-08","epss":0.11844,"percentile":0.95998}],"risk":5.922000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9948"},"relatedVulnerabilities":[{"id":"CVE-2019-9948","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9948","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9948","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9948","date":"2026-10-08","epss":0.11844,"percentile":0.95998}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.html","http://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python-Updates.html","http://www.securityfocus.com/bid/107549","https://access.redhat.com/errata/RHSA-2019:1700","https://access.redhat.com/errata/RHSA-2019:2030","https://access.redhat.com/errata/RHSA-2019:3335","https://access.redhat.com/errata/RHSA-2019:3520","https://bugs.python.org/issue35907","https://github.com/python/cpython/pull/11842","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/","https://seclists.org/bugtraq/2019/Oct/29","https://security.gentoo.org/glsa/202003-26","https://security.netapp.com/advisory/ntap-20190404-0004/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9948","description":"urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-9948","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9948","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9948","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9948","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9948","date":"2026-10-08","epss":0.11844,"percentile":0.95998}],"risk":5.922000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9948"},"relatedVulnerabilities":[{"id":"CVE-2019-9948","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9948","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9948","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9948","date":"2026-10-08","epss":0.11844,"percentile":0.95998}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.html","http://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python-Updates.html","http://www.securityfocus.com/bid/107549","https://access.redhat.com/errata/RHSA-2019:1700","https://access.redhat.com/errata/RHSA-2019:2030","https://access.redhat.com/errata/RHSA-2019:3335","https://access.redhat.com/errata/RHSA-2019:3520","https://bugs.python.org/issue35907","https://github.com/python/cpython/pull/11842","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/","https://seclists.org/bugtraq/2019/Oct/29","https://security.gentoo.org/glsa/202003-26","https://security.netapp.com/advisory/ntap-20190404-0004/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9948","description":"urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9948","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9948","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9948","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9948","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9948","date":"2026-10-08","epss":0.11844,"percentile":0.95998}],"risk":5.922000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9948"},"relatedVulnerabilities":[{"id":"CVE-2019-9948","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9948","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9948","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9948","date":"2026-10-08","epss":0.11844,"percentile":0.95998}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.html","http://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python-Updates.html","http://www.securityfocus.com/bid/107549","https://access.redhat.com/errata/RHSA-2019:1700","https://access.redhat.com/errata/RHSA-2019:2030","https://access.redhat.com/errata/RHSA-2019:3335","https://access.redhat.com/errata/RHSA-2019:3520","https://bugs.python.org/issue35907","https://github.com/python/cpython/pull/11842","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/","https://seclists.org/bugtraq/2019/Oct/29","https://security.gentoo.org/glsa/202003-26","https://security.netapp.com/advisory/ntap-20190404-0004/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9948","description":"urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h3cw-g4mq-c5x2","versionConstraint":">=2.0.0,<=2.9.10.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-h3cw-g4mq-c5x2","fix":{"state":"fixed","versions":["2.9.10.6"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-24616","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-24616","date":"2026-10-08","epss":0.0758,"percentile":0.94386}],"risk":5.912400000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-24616","https://github.com/FasterXML/jackson-databind/issues/2814","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200904-0006/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://github.com/FasterXML/jackson-databind/commit/3d97153944f7de9c19c1b3637b33d3cf1fbbe4d7"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h3cw-g4mq-c5x2","description":"Code Injection in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-24616","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-24616","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-24616","date":"2026-10-08","epss":0.0758,"percentile":0.94386}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2814","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200904-0006/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-24616","description":"FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP)."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5949-rw7g-wx7w","versionConstraint":">=2.7.0,<2.9.10.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5949-rw7g-wx7w","fix":{"state":"fixed","versions":["2.9.10.7"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-20190","cwe":"CWE-502","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-20190","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-20190","date":"2026-10-08","epss":0.07483,"percentile":0.94328}],"risk":5.83674,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-20190","https://github.com/FasterXML/jackson-databind/issues/2854","https://github.com/FasterXML/jackson-databind/commit/7dbf51bf78d157098074a20bd9da39bd48c18e4a","https://bugzilla.redhat.com/show_bug.cgi?id=1916633","https://lists.apache.org/thread.html/r380e9257bacb8551ee6fcf2c59890ae9477b2c78e553fa9ea08e9d9a@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://security.netapp.com/advisory/ntap-20210219-0008"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5949-rw7g-wx7w","description":"Deserialization of untrusted data in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2021-20190","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:C","metrics":{"baseScore":8.3,"impactScore":8.6,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-20190","cwe":"CWE-502","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-20190","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-20190","date":"2026-10-08","epss":0.07483,"percentile":0.94328}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1916633","https://github.com/FasterXML/jackson-databind/issues/2854","https://lists.apache.org/thread.html/r380e9257bacb8551ee6fcf2c59890ae9477b2c78e553fa9ea08e9d9a%40%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210219-0008/","https://www.oracle.com//security-alerts/cpujul2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-20190","description":"A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qjw2-hr98-qgfh","versionConstraint":">=2.7.0,<=2.9.10.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qjw2-hr98-qgfh","fix":{"state":"fixed","versions":["2.9.10.6"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-24750","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-24750","date":"2026-10-08","epss":0.07327,"percentile":0.94239}],"risk":5.71506,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-24750","https://github.com/FasterXML/jackson-databind/issues/2798","https://github.com/FasterXML/jackson-databind/commit/ad5a630174f08d279504bc51ebba8772fd71b86b","https://security.netapp.com/advisory/ntap-20201009-0003/","https://www.oracle.com/security-alerts/cpujan2021.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://github.com/FasterXML/jackson-databind/commit/2118e71325486c68f089a9761c9d8a11b4ddd1cb","https://www.oracle.com/security-alerts/cpuapr2022.html","https://github.com/FasterXML/jackson-databind/commit/6cc9f1a1af323cd156f5668a47e43bab324ae16f"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qjw2-hr98-qgfh","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-24750","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-24750","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-24750","date":"2026-10-08","epss":0.07327,"percentile":0.94239}],"urls":["https://github.com/FasterXML/jackson-databind/commit/ad5a630174f08d279504bc51ebba8772fd71b86b","https://github.com/FasterXML/jackson-databind/issues/2798","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20201009-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-24750","description":"FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mx7p-6679-8g3q","versionConstraint":">=2.9.0,<2.9.10.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mx7p-6679-8g3q","fix":{"state":"fixed","versions":["2.9.10.1"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.10.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16942","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-16942","date":"2026-10-08","epss":0.05728,"percentile":0.9285}],"risk":5.38432,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-16942","https://github.com/FasterXML/jackson-databind/issues/2478","https://issues.apache.org/jira/browse/GEODE-7255","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://access.redhat.com/errata/RHSA-2019:3901","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/7782a937c9259a58337ee36b2961f00e2d744feafc13084e176d0df5@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/a430dbc9be874c41314cc69e697384567a9a24025e819d9485547954@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b2e23c94f9dfef53e04c492e5d02e5c75201734be7adc73a49ef2370@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://seclists.org/bugtraq/2019/Oct/6","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/FasterXML/jackson-databind/commit/328a0f833daf6baa443ac3b37c818a0204714b0b","https://github.com/FasterXML/jackson-databind/commit/54aa38d87dcffa5ccc23e64922e9536c82c1b9c8","https://github.com/FasterXML/jackson-databind/commit/9593e16cf5a3d289a9c584f7123639655de9ddac","https://github.com/FasterXML/jackson-databind/commit/bc67eb11a7cf57561f861ff16f879f1fceb5779f","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT","https://security.netapp.com/advisory/ntap-20191017-0006"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mx7p-6679-8g3q","description":"Polymorphic Typing in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-16942","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16942","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-16942","date":"2026-10-08","epss":0.05728,"percentile":0.9285}],"urls":["https://access.redhat.com/errata/RHSA-2019:3901","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://github.com/FasterXML/jackson-databind/issues/2478","https://issues.apache.org/jira/browse/GEODE-7255","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/7782a937c9259a58337ee36b2961f00e2d744feafc13084e176d0df5%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/a430dbc9be874c41314cc69e697384567a9a24025e819d9485547954%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b2e23c94f9dfef53e04c492e5d02e5c75201734be7adc73a49ef2370%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20191017-0006/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16942","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling."}]},{"artifact":{"id":"893cc2224572c13b","cpes":["cpe:2.3:a:libx11-6:libx11-6:2\\:1.6.4-3ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-6:libx11_6:2\\:1.6.4-3ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11-6:2\\:1.6.4-3ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11_6:2\\:1.6.4-3ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-6:2\\:1.6.4-3ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_6:2\\:1.6.4-3ubuntu0.1:*:*:*:*:*:*:*"],"name":"libx11-6","purl":"pkg:deb/ubuntu/libx11-6@2%3A1.6.4-3ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=libx11","type":"deb","version":"2:1.6.4-3ubuntu0.1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-6/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libx11-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"fix":{"suggestedVersion":"2:1.6.4-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-31535","versionConstraint":"< 2:1.6.4-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"libx11","version":"2:1.6.4-3ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-31535","fix":{"state":"fixed","versions":["2:1.6.4-3ubuntu0.4"],"available":[{"date":"2021-05-25","kind":"advisory","version":"2:1.6.4-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-31535","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31535","date":"2026-10-08","epss":0.10634,"percentile":0.95693}],"risk":5.317,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-31535"},"relatedVulnerabilities":[{"id":"CVE-2021-31535","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-31535","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31535","date":"2026-10-08","epss":0.10634,"percentile":0.95693}],"urls":["http://packetstormsecurity.com/files/162737/libX11-Insufficient-Length-Check-Injection.html","http://seclists.org/fulldisclosure/2021/May/52","http://www.openwall.com/lists/oss-security/2021/05/18/2","https://gitlab.freedesktop.org/xorg/lib/libx11/-/commit/8d2e02ae650f00c4a53deb625211a0527126c605","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cusers.kafka.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/05/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEOT4RLB76RVPJQKGGTIKTBIOLHX2NR6/","https://lists.freedesktop.org/archives/xorg/","https://lists.x.org/archives/xorg-announce/2021-May/003088.html","https://security.gentoo.org/glsa/202105-16","https://security.netapp.com/advisory/ntap-20210813-0001/","https://unparalleled.eu/blog/2021/20210518-using-xterm-to-navigate-the-huge-color-space/","https://unparalleled.eu/publications/2021/advisory-unpar-2021-1.txt","https://www.debian.org/security/2021/dsa-4920","https://www.openwall.com/lists/oss-security/2021/05/18/2","https://www.openwall.com/lists/oss-security/2021/05/18/3"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-31535","description":"LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request (intended for server-side color lookup) contains a flaw allowing a client to send color-name requests with a name longer than the maximum size allowed by the protocol (and also longer than the maximum packet size for normal-sized packets). The user-controlled data exceeding the maximum size is then interpreted by the server as additional X protocol requests and executed, e.g., to disable X server authorization completely. For example, if the victim encounters malicious terminal control sequences for color codes, then the attacker may be able to take full control of the running graphical session."}]},{"artifact":{"id":"a870c26a0651e2df","cpes":["cpe:2.3:a:libx11-data:libx11-data:2\\:1.6.4-3ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-data:libx11_data:2\\:1.6.4-3ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11-data:2\\:1.6.4-3ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11_data:2\\:1.6.4-3ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-data:2\\:1.6.4-3ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_data:2\\:1.6.4-3ubuntu0.1:*:*:*:*:*:*:*"],"name":"libx11-data","purl":"pkg:deb/ubuntu/libx11-data@2%3A1.6.4-3ubuntu0.1?arch=all&distro=ubuntu-18.04&upstream=libx11","type":"deb","version":"2:1.6.4-3ubuntu0.1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-data/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libx11-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libx11-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libx11-data.list"}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"fix":{"suggestedVersion":"2:1.6.4-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-31535","versionConstraint":"< 2:1.6.4-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"libx11","version":"2:1.6.4-3ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-31535","fix":{"state":"fixed","versions":["2:1.6.4-3ubuntu0.4"],"available":[{"date":"2021-05-25","kind":"advisory","version":"2:1.6.4-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-31535","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31535","date":"2026-10-08","epss":0.10634,"percentile":0.95693}],"risk":5.317,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-31535"},"relatedVulnerabilities":[{"id":"CVE-2021-31535","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-31535","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31535","date":"2026-10-08","epss":0.10634,"percentile":0.95693}],"urls":["http://packetstormsecurity.com/files/162737/libX11-Insufficient-Length-Check-Injection.html","http://seclists.org/fulldisclosure/2021/May/52","http://www.openwall.com/lists/oss-security/2021/05/18/2","https://gitlab.freedesktop.org/xorg/lib/libx11/-/commit/8d2e02ae650f00c4a53deb625211a0527126c605","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cusers.kafka.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/05/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEOT4RLB76RVPJQKGGTIKTBIOLHX2NR6/","https://lists.freedesktop.org/archives/xorg/","https://lists.x.org/archives/xorg-announce/2021-May/003088.html","https://security.gentoo.org/glsa/202105-16","https://security.netapp.com/advisory/ntap-20210813-0001/","https://unparalleled.eu/blog/2021/20210518-using-xterm-to-navigate-the-huge-color-space/","https://unparalleled.eu/publications/2021/advisory-unpar-2021-1.txt","https://www.debian.org/security/2021/dsa-4920","https://www.openwall.com/lists/oss-security/2021/05/18/2","https://www.openwall.com/lists/oss-security/2021/05/18/3"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-31535","description":"LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request (intended for server-side color lookup) contains a flaw allowing a client to send color-name requests with a name longer than the maximum size allowed by the protocol (and also longer than the maximum packet size for normal-sized packets). The user-controlled data exceeding the maximum size is then interpreted by the server as additional X protocol requests and executed, e.g., to disable X server authorization completely. For example, if the victim encounters malicious terminal control sequences for color codes, then the attacker may be able to take full control of the running graphical session."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-1971","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-1971","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.7"],"available":[{"date":"2020-12-08","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-1971","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-1971","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-1971","date":"2026-10-08","epss":0.07051,"percentile":0.94041}],"risk":5.28825,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-1971"},"relatedVulnerabilities":[{"id":"CVE-2020-1971","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1971","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-1971","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-1971","date":"2026-10-08","epss":0.07051,"percentile":0.94041}],"urls":["http://www.openwall.com/lists/oss-security/2021/09/14/2","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2154ab83e14ede338d2ede9bbe5cdfce5d5a6c9e","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=f960d81215ebf3f65e03d4d5d857fb9b666d6920","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44676","https://lists.apache.org/thread.html/r63c6f2dd363d9b514d0a4bcf624580616a679898cc14c109a49b750c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rbb769f771711fb274e0a4acb1b5911c8aab544a6ac5e8c12d40c5143%40%3Ccommits.pulsar.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/12/msg00020.html","https://lists.debian.org/debian-lts-announce/2020/12/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DGSI34Y5LQ5RYXN4M2I5ZQT65LFVDOUU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PWPSSZNZOBJU2YR6Z4TGHXKYW3YP5QG7/","https://security.FreeBSD.org/advisories/FreeBSD-SA-20:33.openssl.asc","https://security.gentoo.org/glsa/202012-13","https://security.netapp.com/advisory/ntap-20201218-0005/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2020/dsa-4807","https://www.openssl.org/news/secadv/20201208.txt","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2020-11","https://www.tenable.com/security/tns-2021-09","https://www.tenable.com/security/tns-2021-10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1971","description":"The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL's s_server, s_client and verify tools have support for the \"-crl_download\" option which implements automatic CRL downloading and this attack has been demonstrated to work against those tools. Note that an unrelated bug means that affected versions of OpenSSL cannot parse or construct correct encodings of EDIPARTYNAME. However it is possible to construct a malformed EDIPARTYNAME that OpenSSL's parser will accept and hence trigger this attack. All OpenSSL 1.1.1 and 1.0.2 versions are affected by this issue. Other OpenSSL releases are out of support and have not been checked. Fixed in OpenSSL 1.1.1i (Affected 1.1.1-1.1.1h). Fixed in OpenSSL 1.0.2x (Affected 1.0.2-1.0.2w)."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-1971","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-1971","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.7"],"available":[{"date":"2020-12-08","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-1971","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-1971","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-1971","date":"2026-10-08","epss":0.07051,"percentile":0.94041}],"risk":5.28825,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-1971"},"relatedVulnerabilities":[{"id":"CVE-2020-1971","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1971","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-1971","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-1971","date":"2026-10-08","epss":0.07051,"percentile":0.94041}],"urls":["http://www.openwall.com/lists/oss-security/2021/09/14/2","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2154ab83e14ede338d2ede9bbe5cdfce5d5a6c9e","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=f960d81215ebf3f65e03d4d5d857fb9b666d6920","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44676","https://lists.apache.org/thread.html/r63c6f2dd363d9b514d0a4bcf624580616a679898cc14c109a49b750c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rbb769f771711fb274e0a4acb1b5911c8aab544a6ac5e8c12d40c5143%40%3Ccommits.pulsar.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/12/msg00020.html","https://lists.debian.org/debian-lts-announce/2020/12/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DGSI34Y5LQ5RYXN4M2I5ZQT65LFVDOUU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PWPSSZNZOBJU2YR6Z4TGHXKYW3YP5QG7/","https://security.FreeBSD.org/advisories/FreeBSD-SA-20:33.openssl.asc","https://security.gentoo.org/glsa/202012-13","https://security.netapp.com/advisory/ntap-20201218-0005/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2020/dsa-4807","https://www.openssl.org/news/secadv/20201208.txt","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2020-11","https://www.tenable.com/security/tns-2021-09","https://www.tenable.com/security/tns-2021-10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1971","description":"The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL's s_server, s_client and verify tools have support for the \"-crl_download\" option which implements automatic CRL downloading and this attack has been demonstrated to work against those tools. Note that an unrelated bug means that affected versions of OpenSSL cannot parse or construct correct encodings of EDIPARTYNAME. However it is possible to construct a malformed EDIPARTYNAME that OpenSSL's parser will accept and hence trigger this attack. All OpenSSL 1.1.1 and 1.0.2 versions are affected by this issue. Other OpenSSL releases are out of support and have not been checked. Fixed in OpenSSL 1.1.1i (Affected 1.1.1-1.1.1h). Fixed in OpenSSL 1.0.2x (Affected 1.0.2-1.0.2w)."}]},{"artifact":{"id":"27ee78362b14237a","cpes":["cpe:2.3:a:apache:commons-io:2.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons_io:2.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons:2.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:io:2.6:*:*:*:*:*:*:*"],"name":"commons-io","purl":"pkg:maven/commons-io/commons-io@2.6","type":"java-archive","version":"2.6","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"commons-io","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/commons-io-2.6.jar","manifestName":"","pomArtifactID":"commons-io","archiveDigests":[{"value":"815893df5f31da2ece4040fe0a12fd44b577afaf","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/commons-io-2.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gwrp-pvrq-jmwv","versionConstraint":"<2.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"commons-io:commons-io","version":"2.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gwrp-pvrq-jmwv","fix":{"state":"fixed","versions":["2.7"],"available":[{"date":"2021-04-27","kind":"first-observed","version":"2.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-29425","cwe":"CWE-20","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2021-29425","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-29425","date":"2026-10-08","epss":0.10549,"percentile":0.95667}],"risk":5.16901,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-29425","https://issues.apache.org/jira/browse/IO-556","https://lists.apache.org/thread.html/r0d73e2071d1f1afe1a15da14c5b6feb2cf17e3871168d5a3c8451436@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r873d5ddafc0a68fd999725e559776dc4971d1ab39c0f5cc81bd9bc04@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r8efcbabde973ea72f5e0933adc48ef1425db5cde850bf641b3993f31@%3Cdev.commons.apache.org%3E","https://lists.apache.org/thread.html/rc359823b5500e9a9a2572678ddb8e01d3505a7ffcadfa8d13b8780ab%40%3Cuser.commons.apache.org%3E","https://lists.apache.org/thread.html/rfd01af05babc95b8949e6d8ea78d9834699e1b06981040dde419a330@%3Cdev.commons.apache.org%3E","https://lists.apache.org/thread.html/r47ab6f68cbba8e730f42c4ea752f3a44eb95fb09064070f2476bb401@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r8569a41d565ca880a4dee0e645dad1cd17ab4a92e68055ad9ebb7375@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/raa053846cae9d497606027816ae87b4e002b2e0eb66cb0dee710e1f5@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/rfa2f08b7c0caf80ca9f4a18bd875918fdd4e894e2ea47942a4589b9c@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r1c2f4683c35696cf6f863e3c107e37ec41305b1930dd40c17260de71@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r27b1eedda37468256c4bb768fde1e8b79b37ec975cbbfd0d65a7ac34@%3Cdev.myfaces.apache.org%3E","https://lists.apache.org/thread.html/r2bc986a070457daca457a54fe71ee09d2584c24dc262336ca32b6a19@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r523a6ffad58f71c4f3761e3cee72df878e48cdc89ebdce933be1475c@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/ra8ef65aedc086d2d3d21492b4c08ae0eb8a3a42cc52e29ba1bc009d8@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/rbebd3e19651baa7a4a5503a9901c95989df9d40602c8e35cb05d3eb5@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe@%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r345330b7858304938b7b8029d02537a116d75265a598c98fa333504a@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r808be7d93b17a7055c1981a8453ae5f0d0fce5855407793c5d0ffffa@%3Cuser.commons.apache.org%3E","https://lists.apache.org/thread.html/rad4ae544747df32ccd58fff5a86cd556640396aeb161aa71dd3d192a@%3Cuser.commons.apache.org%3E","https://lists.apache.org/thread.html/r01b4a1fcdf3311c936ce33d75a9398b6c255f00c1a2f312ac21effe1@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r0bfa8f7921abdfae788b1f076a12f73a92c93cc0a6e1083bce0027c5@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r20416f39ca7f7344e7d76fe4d7063bb1d91ad106926626e7e83fb346@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r2345b49dbffa8a5c3c589c082fe39228a2c1d14f11b96c523da701db@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r2df50af2641d38f432ef025cd2ba5858215cc0cf3fc10396a674ad2e@%3Cpluto-scm.portals.apache.org%3E","https://lists.apache.org/thread.html/r477c285126ada5c3b47946bb702cb222ac4e7fd3100c8549bdd6d3b2@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r86528f4b7d222aed7891e7ac03d69a0db2a2dfa17b86ac3470d7f374@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r8bfc7235e6b39d90e6f446325a5a44c3e9e50da18860fdabcee23e29@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r92ea904f4bae190b03bd42a4355ce3c2fbe8f36ab673e03f6ca3f9fa@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc10fa20ef4d13cbf6ebe0b06b5edb95466a1424a9b7673074ed03260@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc2dd3204260e9227a67253ef68b6f1599446005bfa0e1ddce4573a80@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/rc5f3df5316c5237b78a3dff5ab95b311ad08e61d418cd992ca7e34ae@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc65f9bc679feffe4589ea0981ee98bc0af9139470f077a91580eeee0@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/rca71a10ca533eb9bfac2d590533f02e6fb9064d3b6aa3ec90fdc4f51@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd09d4ab3e32e4b3a480e2ff6ff118712981ca82e817f28f2a85652a6@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re41e9967bee064e7369411c28f0f5b2ad28b8334907c9c6208017279@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/red3aea910403d8620c73e1c7b9c9b145798d0469eb3298a7be7891af@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rfcd2c649c205f12b72dde044f905903460669a220a2eb7e12652d19d@%3Cdev.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/08/msg00016.html","https://lists.apache.org/thread.html/r4050f9f6b42ebfa47a98cbdee4aabed4bb5fb8093db7dbb88faceba2@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r462db908acc1e37c455e11b1a25992b81efd18e641e7e0ceb1b6e046@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r5149f78be265be69d34eacb4e4b0fc7c9c697bcdfa91a1c1658d717b@%3Cissues.zookeeper.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://arxiv.org/pdf/2306.05534.pdf","https://github.com/jensdietrich/xshady-release/tree/main/CVE-2021-29425","https://security.netapp.com/advisory/ntap-20220210-0004"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gwrp-pvrq-jmwv","description":"Path Traversal and Improper Input Validation in Apache Commons IO"},"relatedVulnerabilities":[{"id":"CVE-2021-29425","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-29425","cwe":"CWE-20","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2021-29425","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-29425","date":"2026-10-08","epss":0.10549,"percentile":0.95667}],"urls":["https://issues.apache.org/jira/browse/IO-556","https://lists.apache.org/thread.html/r01b4a1fcdf3311c936ce33d75a9398b6c255f00c1a2f312ac21effe1%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r0bfa8f7921abdfae788b1f076a12f73a92c93cc0a6e1083bce0027c5%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r0d73e2071d1f1afe1a15da14c5b6feb2cf17e3871168d5a3c8451436%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r1c2f4683c35696cf6f863e3c107e37ec41305b1930dd40c17260de71%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r20416f39ca7f7344e7d76fe4d7063bb1d91ad106926626e7e83fb346%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r2345b49dbffa8a5c3c589c082fe39228a2c1d14f11b96c523da701db%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r27b1eedda37468256c4bb768fde1e8b79b37ec975cbbfd0d65a7ac34%40%3Cdev.myfaces.apache.org%3E","https://lists.apache.org/thread.html/r2bc986a070457daca457a54fe71ee09d2584c24dc262336ca32b6a19%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r2df50af2641d38f432ef025cd2ba5858215cc0cf3fc10396a674ad2e%40%3Cpluto-scm.portals.apache.org%3E","https://lists.apache.org/thread.html/r345330b7858304938b7b8029d02537a116d75265a598c98fa333504a%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r4050f9f6b42ebfa47a98cbdee4aabed4bb5fb8093db7dbb88faceba2%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r462db908acc1e37c455e11b1a25992b81efd18e641e7e0ceb1b6e046%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r477c285126ada5c3b47946bb702cb222ac4e7fd3100c8549bdd6d3b2%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r47ab6f68cbba8e730f42c4ea752f3a44eb95fb09064070f2476bb401%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r5149f78be265be69d34eacb4e4b0fc7c9c697bcdfa91a1c1658d717b%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r523a6ffad58f71c4f3761e3cee72df878e48cdc89ebdce933be1475c%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r808be7d93b17a7055c1981a8453ae5f0d0fce5855407793c5d0ffffa%40%3Cuser.commons.apache.org%3E","https://lists.apache.org/thread.html/r8569a41d565ca880a4dee0e645dad1cd17ab4a92e68055ad9ebb7375%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r86528f4b7d222aed7891e7ac03d69a0db2a2dfa17b86ac3470d7f374%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r873d5ddafc0a68fd999725e559776dc4971d1ab39c0f5cc81bd9bc04%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r8bfc7235e6b39d90e6f446325a5a44c3e9e50da18860fdabcee23e29%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r8efcbabde973ea72f5e0933adc48ef1425db5cde850bf641b3993f31%40%3Cdev.commons.apache.org%3E","https://lists.apache.org/thread.html/r92ea904f4bae190b03bd42a4355ce3c2fbe8f36ab673e03f6ca3f9fa%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra8ef65aedc086d2d3d21492b4c08ae0eb8a3a42cc52e29ba1bc009d8%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/raa053846cae9d497606027816ae87b4e002b2e0eb66cb0dee710e1f5%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/rad4ae544747df32ccd58fff5a86cd556640396aeb161aa71dd3d192a%40%3Cuser.commons.apache.org%3E","https://lists.apache.org/thread.html/rbebd3e19651baa7a4a5503a9901c95989df9d40602c8e35cb05d3eb5%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/rc10fa20ef4d13cbf6ebe0b06b5edb95466a1424a9b7673074ed03260%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc2dd3204260e9227a67253ef68b6f1599446005bfa0e1ddce4573a80%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/rc359823b5500e9a9a2572678ddb8e01d3505a7ffcadfa8d13b8780ab%40%3Cuser.commons.apache.org%3E","https://lists.apache.org/thread.html/rc5f3df5316c5237b78a3dff5ab95b311ad08e61d418cd992ca7e34ae%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc65f9bc679feffe4589ea0981ee98bc0af9139470f077a91580eeee0%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/rca71a10ca533eb9bfac2d590533f02e6fb9064d3b6aa3ec90fdc4f51%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd09d4ab3e32e4b3a480e2ff6ff118712981ca82e817f28f2a85652a6%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re41e9967bee064e7369411c28f0f5b2ad28b8334907c9c6208017279%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/red3aea910403d8620c73e1c7b9c9b145798d0469eb3298a7be7891af%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rfa2f08b7c0caf80ca9f4a18bd875918fdd4e894e2ea47942a4589b9c%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/rfcd2c649c205f12b72dde044f905903460669a220a2eb7e12652d19d%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rfd01af05babc95b8949e6d8ea78d9834699e1b06981040dde419a330%40%3Cdev.commons.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/08/msg00016.html","https://security.netapp.com/advisory/ntap-20220210-0004/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-29425","description":"In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like \"//../foo\", or \"\\\\..\\foo\", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus \"limited\" path traversal), if the calling code would use the result to construct a path value."}]},{"artifact":{"id":"0b1c74783f88c915","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.22.0-1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20346","versionConstraint":"< 3.22.0-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-20346","fix":{"state":"fixed","versions":["3.22.0-1ubuntu0.1"],"available":[{"date":"2019-06-19","kind":"advisory","version":"3.22.0-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-20346","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20346","date":"2026-10-08","epss":0.10312,"percentile":0.95595}],"risk":5.156000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-20346"},"relatedVulnerabilities":[{"id":"CVE-2018-20346","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20346","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20346","date":"2026-10-08","epss":0.10312,"percentile":0.95595}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00040.html","http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.html","http://www.securityfocus.com/bid/106323","https://access.redhat.com/articles/3758321","https://blade.tencent.com/magellan/index_en.html","https://bugzilla.redhat.com/show_bug.cgi?id=1659379","https://bugzilla.redhat.com/show_bug.cgi?id=1659677","https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html","https://chromium.googlesource.com/chromium/src/+/c368e30ae55600a1c3c9cb1710a54f9c55de786e","https://crbug.com/900910","https://github.com/zhuowei/worthdoingbadly.com/blob/master/_posts/2018-12-14-sqlitebug.html","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://lists.debian.org/debian-lts-announce/2018/12/msg00012.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PU4NZ6DDU4BEM3ACM3FM6GLEPX56ZQXK/","https://news.ycombinator.com/item?id=18685296","https://security.gentoo.org/glsa/201904-21","https://sqlite.org/src/info/940f2adc8541a838","https://sqlite.org/src/info/d44318f59044162e","https://support.apple.com/HT209443","https://support.apple.com/HT209446","https://support.apple.com/HT209447","https://support.apple.com/HT209448","https://support.apple.com/HT209450","https://support.apple.com/HT209451","https://usn.ubuntu.com/4019-1/","https://usn.ubuntu.com/4019-2/","https://worthdoingbadly.com/sqlitebug/","https://www.freebsd.org/security/advisories/FreeBSD-EN-19:03.sqlite.asc","https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg113218.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.sqlite.org/releaselog/3_25_3.html","https://www.synology.com/security/advisory/Synology_SA_18_61"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20346","description":"SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan."}]},{"artifact":{"id":"3445236446ec4939","cpes":["cpe:2.3:a:krb5-locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5-locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"krb5-locales","purl":"pkg:deb/ubuntu/krb5-locales@1.16-2ubuntu0.1?arch=all&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/krb5-locales/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/krb5-locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/krb5-locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/krb5-locales.list"}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-36222","versionConstraint":"< 1.16-2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-36222","fix":{"state":"fixed","versions":["1.16-2ubuntu0.4"],"available":[{"date":"2023-03-16","kind":"advisory","version":"1.16-2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"risk":5.138,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-36222"},"relatedVulnerabilities":[{"id":"CVE-2021-36222","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"urls":["https://github.com/krb5/krb5/commit/fc98f520caefff2e5ee9a0026fdf5109944b3562","https://github.com/krb5/krb5/releases","https://security.netapp.com/advisory/ntap-20211022-0003/","https://security.netapp.com/advisory/ntap-20211104-0007/","https://web.mit.edu/kerberos/advisories/","https://www.debian.org/security/2021/dsa-4944","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-36222","description":"ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation."}]},{"artifact":{"id":"f3fc35a2cb3401bd","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/ubuntu/libgssapi-krb5-2@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-36222","versionConstraint":"< 1.16-2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-36222","fix":{"state":"fixed","versions":["1.16-2ubuntu0.4"],"available":[{"date":"2023-03-16","kind":"advisory","version":"1.16-2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"risk":5.138,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-36222"},"relatedVulnerabilities":[{"id":"CVE-2021-36222","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"urls":["https://github.com/krb5/krb5/commit/fc98f520caefff2e5ee9a0026fdf5109944b3562","https://github.com/krb5/krb5/releases","https://security.netapp.com/advisory/ntap-20211022-0003/","https://security.netapp.com/advisory/ntap-20211104-0007/","https://web.mit.edu/kerberos/advisories/","https://www.debian.org/security/2021/dsa-4944","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-36222","description":"ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation."}]},{"artifact":{"id":"ce64c2275844a0e2","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/ubuntu/libk5crypto3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-36222","versionConstraint":"< 1.16-2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-36222","fix":{"state":"fixed","versions":["1.16-2ubuntu0.4"],"available":[{"date":"2023-03-16","kind":"advisory","version":"1.16-2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"risk":5.138,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-36222"},"relatedVulnerabilities":[{"id":"CVE-2021-36222","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"urls":["https://github.com/krb5/krb5/commit/fc98f520caefff2e5ee9a0026fdf5109944b3562","https://github.com/krb5/krb5/releases","https://security.netapp.com/advisory/ntap-20211022-0003/","https://security.netapp.com/advisory/ntap-20211104-0007/","https://web.mit.edu/kerberos/advisories/","https://www.debian.org/security/2021/dsa-4944","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-36222","description":"ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation."}]},{"artifact":{"id":"a0e77fe46f00e692","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/ubuntu/libkrb5-3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-36222","versionConstraint":"< 1.16-2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-36222","fix":{"state":"fixed","versions":["1.16-2ubuntu0.4"],"available":[{"date":"2023-03-16","kind":"advisory","version":"1.16-2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"risk":5.138,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-36222"},"relatedVulnerabilities":[{"id":"CVE-2021-36222","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"urls":["https://github.com/krb5/krb5/commit/fc98f520caefff2e5ee9a0026fdf5109944b3562","https://github.com/krb5/krb5/releases","https://security.netapp.com/advisory/ntap-20211022-0003/","https://security.netapp.com/advisory/ntap-20211104-0007/","https://web.mit.edu/kerberos/advisories/","https://www.debian.org/security/2021/dsa-4944","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-36222","description":"ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation."}]},{"artifact":{"id":"402827dd4cb6593f","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/ubuntu/libkrb5support0@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-36222","versionConstraint":"< 1.16-2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-36222","fix":{"state":"fixed","versions":["1.16-2ubuntu0.4"],"available":[{"date":"2023-03-16","kind":"advisory","version":"1.16-2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"risk":5.138,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-36222"},"relatedVulnerabilities":[{"id":"CVE-2021-36222","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"urls":["https://github.com/krb5/krb5/commit/fc98f520caefff2e5ee9a0026fdf5109944b3562","https://github.com/krb5/krb5/releases","https://security.netapp.com/advisory/ntap-20211022-0003/","https://security.netapp.com/advisory/ntap-20211104-0007/","https://web.mit.edu/kerberos/advisories/","https://www.debian.org/security/2021/dsa-4944","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-36222","description":"ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9vvp-fxw6-jcxr","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-9vvp-fxw6-jcxr","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11113","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-11113","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-11113","date":"2026-10-08","epss":0.06278,"percentile":0.93407}],"risk":5.116570000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-11113","https://github.com/FasterXML/jackson-databind/issues/2670","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://github.com/FasterXML/jackson-databind/commit/e2ba12d5d60715d95105e3e790fc234cfb59893d","https://security.netapp.com/advisory/ntap-20200403-0002"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9vvp-fxw6-jcxr","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-11113","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11113","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-11113","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-11113","date":"2026-10-08","epss":0.06278,"percentile":0.93407}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2670","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-11113","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa)."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gjmw-vf9h-g25v","versionConstraint":">=2.9.0,<2.9.10.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gjmw-vf9h-g25v","fix":{"state":"fixed","versions":["2.9.10.1"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.10.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-17531","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-17531","date":"2026-10-08","epss":0.05373,"percentile":0.92451}],"risk":5.05062,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-17531","https://github.com/FasterXML/jackson-databind/issues/2498","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://access.redhat.com/errata/RHSA-2019:4192","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://lists.apache.org/thread.html/b3c90d38f99db546de60fea65f99a924d540fae2285f014b79606ca5@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html","https://security.netapp.com/advisory/ntap-20191024-0005/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/FasterXML/jackson-databind/commit/b5a304a98590b6bb766134f9261e6566dcbbb6d0"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gjmw-vf9h-g25v","description":"jackson-databind polymorphic typing issue"},"relatedVulnerabilities":[{"id":"CVE-2019-17531","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-17531","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-17531","date":"2026-10-08","epss":0.05373,"percentile":0.92451}],"urls":["https://access.redhat.com/errata/RHSA-2019:4192","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://github.com/FasterXML/jackson-databind/issues/2498","https://lists.apache.org/thread.html/b3c90d38f99db546de60fea65f99a924d540fae2285f014b79606ca5%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20191024-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-17531","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload."}]},{"artifact":{"id":"1d5068aaeba012b0","cpes":["cpe:2.3:a:org.jsoup:jsoup:1.11.3:*:*:*:*:*:*:*","cpe:2.3:a:jsoup:jsoup:1.11.3:*:*:*:*:*:*:*"],"name":"jsoup","purl":"pkg:maven/org.jsoup/jsoup@1.11.3","type":"java-archive","version":"1.11.3","language":"java","licenses":["https://jsoup.org/license"],"metadata":{"pomGroupID":"org.jsoup","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jsoup-1.11.3.jar","manifestName":"","pomArtifactID":"jsoup","archiveDigests":[{"value":"36da09a8f68484523fa2aaa100399d612b247d67","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jsoup-1.11.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.14.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m72m-mhq2-9p6c","versionConstraint":"<1.14.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jsoup:jsoup","version":"1.11.3"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-m72m-mhq2-9p6c","fix":{"state":"fixed","versions":["1.14.2"],"available":[{"date":"2021-08-24","kind":"first-observed","version":"1.14.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-37714","cwe":"CWE-248","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2021-37714","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2021-37714","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-37714","date":"2026-10-08","epss":0.06689,"percentile":0.93738}],"risk":5.01675,"urls":["https://github.com/jhy/jsoup/security/advisories/GHSA-m72m-mhq2-9p6c","https://nvd.nist.gov/vuln/detail/CVE-2021-37714","https://jsoup.org/news/release-1.14.1","https://jsoup.org/news/release-1.14.2","https://lists.apache.org/thread.html/r685c5235235ad0c26e86d0ee987fb802c9675de6081dbf0516464e0b@%3Cnotifications.james.apache.org%3E","https://lists.apache.org/thread.html/r97404676a5cf591988faedb887d64e278f522adcaa823d89ca69defe@%3Cnotifications.james.apache.org%3E","https://lists.apache.org/thread.html/rc3354080fc67fb50b45b3c2d12dc4ca2a3c1c78dad3d3ba012c038aa@%3Cnotifications.james.apache.org%3E","https://lists.apache.org/thread.html/r50e9c9466c592ca9d707a5dea549524d19e3287da08d8392f643960e@%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r215009dbf7467a9f6506d0c0024cb36cad30071010e62c9352cfaaf0@%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r377b93d79817ce649e9e68b3456e6f499747ef1643fa987b342e082e@%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r3d71f18adb78e50f626dde689161ca63d3b7491bd9718fcddfaecba7@%3Cissues.maven.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2022.html","https://security.netapp.com/advisory/ntap-20220210-0022/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m72m-mhq2-9p6c","description":"Uncaught Exception in jsoup"},"relatedVulnerabilities":[{"id":"CVE-2021-37714","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-37714","cwe":"CWE-248","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2021-37714","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2021-37714","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-37714","date":"2026-10-08","epss":0.06689,"percentile":0.93738}],"urls":["https://github.com/jhy/jsoup/security/advisories/GHSA-m72m-mhq2-9p6c","https://jsoup.org/news/release-1.14.1","https://jsoup.org/news/release-1.14.2","https://lists.apache.org/thread.html/r215009dbf7467a9f6506d0c0024cb36cad30071010e62c9352cfaaf0%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r377b93d79817ce649e9e68b3456e6f499747ef1643fa987b342e082e%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r3d71f18adb78e50f626dde689161ca63d3b7491bd9718fcddfaecba7%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r50e9c9466c592ca9d707a5dea549524d19e3287da08d8392f643960e%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r685c5235235ad0c26e86d0ee987fb802c9675de6081dbf0516464e0b%40%3Cnotifications.james.apache.org%3E","https://lists.apache.org/thread.html/r97404676a5cf591988faedb887d64e278f522adcaa823d89ca69defe%40%3Cnotifications.james.apache.org%3E","https://lists.apache.org/thread.html/rc3354080fc67fb50b45b3c2d12dc4ca2a3c1c78dad3d3ba012c038aa%40%3Cnotifications.james.apache.org%3E","https://security.netapp.com/advisory/ntap-20220210-0022/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-37714","description":"jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes."}]},{"artifact":{"id":"116ba9b4dedae730","cpes":["cpe:2.3:a:metastuff-ltd-:dom4j:1.6.1:*:*:*:*:*:*:*","cpe:2.3:a:metastuff_ltd_:dom4j:1.6.1:*:*:*:*:*:*:*","cpe:2.3:a:org.dom4j:dom4j:1.6.1:*:*:*:*:*:*:*","cpe:2.3:a:dom4j:dom4j:1.6.1:*:*:*:*:*:*:*"],"name":"dom4j","purl":"pkg:maven/org.dom4j/dom4j@1.6.1","type":"java-archive","version":"1.6.1","language":"java","licenses":["sha256:9a6b4e9e1668b2cc31453527ee07a1a68495f4cae149cfe03a8c955e6093ec55"],"metadata":{"pomGroupID":"org.dom4j","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/dom4j-1.6.1.jar","manifestName":"","pomArtifactID":"dom4j","archiveDigests":[{"value":"5d3ccc056b6f056dbf0dddfdf43894b9065a8f94","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/dom4j-1.6.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.0.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6pcc-3rfx-4gpm","versionConstraint":"<2.0.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.dom4j:dom4j","version":"1.6.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6pcc-3rfx-4gpm","fix":{"state":"fixed","versions":["2.0.3"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.0.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000632","cwe":"CWE-91","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000632","date":"2026-10-08","epss":0.0657,"percentile":0.93655}],"risk":4.9275,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-1000632","https://github.com/dom4j/dom4j/issues/48","https://github.com/dom4j/dom4j/commit/c2a99d7dee8ce7a4e5bef134bb781a6672bd8a0f","https://github.com/dom4j/dom4j/commit/e598eb43d418744c4dbf62f647dd2381c9ce9387","https://ihacktoprotect.com/post/dom4j-xml-injection/","https://access.redhat.com/errata/RHSA-2019:0362","https://access.redhat.com/errata/RHSA-2019:0364","https://access.redhat.com/errata/RHSA-2019:0365","https://access.redhat.com/errata/RHSA-2019:0380","https://access.redhat.com/errata/RHSA-2019:1159","https://access.redhat.com/errata/RHSA-2019:1160","https://access.redhat.com/errata/RHSA-2019:1161","https://access.redhat.com/errata/RHSA-2019:1162","https://access.redhat.com/errata/RHSA-2019:3172","https://lists.apache.org/thread.html/00571f362a7a2470fba50a31282c65637c40d2e21ebe6ee535a4ed74@%3Ccommits.maven.apache.org%3E","https://lists.apache.org/thread.html/4a77652531d62299a30815cf5f233af183425db8e3c9a824a814e768@%3Cdev.maven.apache.org%3E","https://lists.apache.org/thread.html/5a020ecaa3c701f408f612f7ba2ee37a021644c4a39da2079ed3ddbc@%3Ccommits.maven.apache.org%3E","https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3E","https://lists.apache.org/thread.html/7e9e78f0e4288fac6591992836d2a80d4df19161e54bd71ab4b8e458@%3Cdev.maven.apache.org%3E","https://lists.apache.org/thread.html/7f6e120e6ed473f4e00dde4c398fc6698eb383bd7857d20513e989ce@%3Cdev.maven.apache.org%3E","https://lists.apache.org/thread.html/9d4c1af6f702c3d6d6f229de57112ddccac8ce44446a01b7937ab9e0@%3Ccommits.maven.apache.org%3E","https://lists.apache.org/thread.html/d7d960b2778e35ec9b4d40c8efd468c7ce7163bcf6489b633491c89f@%3Cdev.maven.apache.org%3E","https://lists.debian.org/debian-lts-announce/2018/09/msg00028.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IOOVVCRQE6ATFD2JM2EMDXOQXTRIVZGP/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJULAHVR3I5SX7OSMXAG75IMNSAYOXGA/","https://security.netapp.com/advisory/ntap-20190530-0001/","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51@%3Cnotifications.freemarker.apache.org%3E"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6pcc-3rfx-4gpm","description":"Dom4j contains a XML Injection vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2018-1000632","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000632","cwe":"CWE-91","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000632","date":"2026-10-08","epss":0.0657,"percentile":0.93655}],"urls":["https://access.redhat.com/errata/RHSA-2019:0362","https://access.redhat.com/errata/RHSA-2019:0364","https://access.redhat.com/errata/RHSA-2019:0365","https://access.redhat.com/errata/RHSA-2019:0380","https://access.redhat.com/errata/RHSA-2019:1159","https://access.redhat.com/errata/RHSA-2019:1160","https://access.redhat.com/errata/RHSA-2019:1161","https://access.redhat.com/errata/RHSA-2019:1162","https://access.redhat.com/errata/RHSA-2019:3172","https://github.com/dom4j/dom4j/commit/e598eb43d418744c4dbf62f647dd2381c9ce9387","https://github.com/dom4j/dom4j/issues/48","https://ihacktoprotect.com/post/dom4j-xml-injection/","https://lists.apache.org/thread.html/00571f362a7a2470fba50a31282c65637c40d2e21ebe6ee535a4ed74%40%3Ccommits.maven.apache.org%3E","https://lists.apache.org/thread.html/4a77652531d62299a30815cf5f233af183425db8e3c9a824a814e768%40%3Cdev.maven.apache.org%3E","https://lists.apache.org/thread.html/5a020ecaa3c701f408f612f7ba2ee37a021644c4a39da2079ed3ddbc%40%3Ccommits.maven.apache.org%3E","https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E","https://lists.apache.org/thread.html/7e9e78f0e4288fac6591992836d2a80d4df19161e54bd71ab4b8e458%40%3Cdev.maven.apache.org%3E","https://lists.apache.org/thread.html/7f6e120e6ed473f4e00dde4c398fc6698eb383bd7857d20513e989ce%40%3Cdev.maven.apache.org%3E","https://lists.apache.org/thread.html/9d4c1af6f702c3d6d6f229de57112ddccac8ce44446a01b7937ab9e0%40%3Ccommits.maven.apache.org%3E","https://lists.apache.org/thread.html/d7d960b2778e35ec9b4d40c8efd468c7ce7163bcf6489b633491c89f%40%3Cdev.maven.apache.org%3E","https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51%40%3Cnotifications.freemarker.apache.org%3E","https://lists.debian.org/debian-lts-announce/2018/09/msg00028.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IOOVVCRQE6ATFD2JM2EMDXOQXTRIVZGP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJULAHVR3I5SX7OSMXAG75IMNSAYOXGA/","https://security.netapp.com/advisory/ntap-20190530-0001/","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000632","description":"dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wh8g-3j2c-rqj5","versionConstraint":">=2.0.0,<=2.9.10.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wh8g-3j2c-rqj5","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-35490","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-35490","date":"2026-10-08","epss":0.06285,"percentile":0.93415}],"risk":4.9023,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-35490","https://github.com/FasterXML/jackson-databind/issues/2986","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/41b8bdb5ccc1d8edb71acf1c8234da235a24249d","https://security.netapp.com/advisory/ntap-20210122-0005"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wh8g-3j2c-rqj5","description":"Serialization gadgets exploit in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-35490","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-35490","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-35490","date":"2026-10-08","epss":0.06285,"percentile":0.93415}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/2986","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210122-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-35490","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-8285","versionConstraint":"< 7.58.0-2ubuntu3.12 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-8285","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.12"],"available":[{"date":"2020-12-09","kind":"advisory","version":"7.58.0-2ubuntu3.12"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-8285","cwe":"CWE-674","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2020-8285","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-8285","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8285","date":"2026-10-08","epss":0.0977,"percentile":0.95425}],"risk":4.885,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-8285"},"relatedVulnerabilities":[{"id":"CVE-2020-8285","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8285","cwe":"CWE-674","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2020-8285","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-8285","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8285","date":"2026-10-08","epss":0.0977,"percentile":0.95425}],"urls":["http://seclists.org/fulldisclosure/2021/Apr/51","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://curl.se/docs/CVE-2020-8285.html","https://github.com/curl/curl/issues/6255","https://hackerone.com/reports/1045844","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/","https://security.gentoo.org/glsa/202012-14","https://security.netapp.com/advisory/ntap-20210122-0007/","https://support.apple.com/kb/HT212325","https://support.apple.com/kb/HT212326","https://support.apple.com/kb/HT212327","https://www.debian.org/security/2021/dsa-4881","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8285","description":"curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.12"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-8285","versionConstraint":"< 7.58.0-2ubuntu3.12 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-8285","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.12"],"available":[{"date":"2020-12-09","kind":"advisory","version":"7.58.0-2ubuntu3.12"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-8285","cwe":"CWE-674","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2020-8285","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-8285","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8285","date":"2026-10-08","epss":0.0977,"percentile":0.95425}],"risk":4.885,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-8285"},"relatedVulnerabilities":[{"id":"CVE-2020-8285","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8285","cwe":"CWE-674","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2020-8285","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-8285","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8285","date":"2026-10-08","epss":0.0977,"percentile":0.95425}],"urls":["http://seclists.org/fulldisclosure/2021/Apr/51","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://curl.se/docs/CVE-2020-8285.html","https://github.com/curl/curl/issues/6255","https://hackerone.com/reports/1045844","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/","https://security.gentoo.org/glsa/202012-14","https://security.netapp.com/advisory/ntap-20210122-0007/","https://support.apple.com/kb/HT212325","https://support.apple.com/kb/HT212326","https://support.apple.com/kb/HT212327","https://www.debian.org/security/2021/dsa-4881","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8285","description":"curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing."}]},{"artifact":{"id":"b85d32abb98a38e9","cpes":["cpe:2.3:a:libpng16-16:libpng16-16:1.6.34-1ubuntu0.18.04.1:*:*:*:*:*:*:*","cpe:2.3:a:libpng16-16:libpng16_16:1.6.34-1ubuntu0.18.04.1:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16:libpng16-16:1.6.34-1ubuntu0.18.04.1:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16:libpng16_16:1.6.34-1ubuntu0.18.04.1:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16-16:1.6.34-1ubuntu0.18.04.1:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16_16:1.6.34-1ubuntu0.18.04.1:*:*:*:*:*:*:*"],"name":"libpng16-16","purl":"pkg:deb/ubuntu/libpng16-16@1.6.34-1ubuntu0.18.04.1?arch=amd64&distro=ubuntu-18.04&upstream=libpng1.6","type":"deb","version":"1.6.34-1ubuntu0.18.04.1","language":"","licenses":["Apache-2.0","BSD-3-clause","BSD-like-with-advertising-clause","GPL-2","GPL-2+","expat","libpng"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpng16-16/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpng16-16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpng16-16:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpng16-16:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libpng1.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.6.34-1ubuntu0.18.04.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-7317","versionConstraint":"< 1.6.34-1ubuntu0.18.04.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"libpng1.6","version":"1.6.34-1ubuntu0.18.04.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-7317","fix":{"state":"fixed","versions":["1.6.34-1ubuntu0.18.04.2"],"available":[{"date":"2019-04-30","kind":"advisory","version":"1.6.34-1ubuntu0.18.04.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-7317","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-7317","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-7317","date":"2026-10-08","epss":0.09393,"percentile":0.95291}],"risk":4.6965,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-7317"},"relatedVulnerabilities":[{"id":"CVE-2019-7317","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-7317","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-7317","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-7317","date":"2026-10-08","epss":0.09393,"percentile":0.95291}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00002.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00029.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00084.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00038.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00044.html","http://packetstormsecurity.com/files/152561/Slackware-Security-Advisory-libpng-Updates.html","http://www.securityfocus.com/bid/108098","https://access.redhat.com/errata/RHSA-2019:1265","https://access.redhat.com/errata/RHSA-2019:1267","https://access.redhat.com/errata/RHSA-2019:1269","https://access.redhat.com/errata/RHSA-2019:1308","https://access.redhat.com/errata/RHSA-2019:1309","https://access.redhat.com/errata/RHSA-2019:1310","https://access.redhat.com/errata/RHSA-2019:2494","https://access.redhat.com/errata/RHSA-2019:2495","https://access.redhat.com/errata/RHSA-2019:2585","https://access.redhat.com/errata/RHSA-2019:2590","https://access.redhat.com/errata/RHSA-2019:2592","https://access.redhat.com/errata/RHSA-2019:2737","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12803","https://github.com/glennrp/libpng/issues/275","https://lists.debian.org/debian-lts-announce/2019/05/msg00032.html","https://lists.debian.org/debian-lts-announce/2019/05/msg00038.html","https://seclists.org/bugtraq/2019/Apr/30","https://seclists.org/bugtraq/2019/Apr/36","https://seclists.org/bugtraq/2019/May/56","https://seclists.org/bugtraq/2019/May/59","https://seclists.org/bugtraq/2019/May/67","https://security.gentoo.org/glsa/201908-02","https://security.netapp.com/advisory/ntap-20190719-0005/","https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03977en_us","https://usn.ubuntu.com/3962-1/","https://usn.ubuntu.com/3991-1/","https://usn.ubuntu.com/3997-1/","https://usn.ubuntu.com/4080-1/","https://usn.ubuntu.com/4083-1/","https://www.debian.org/security/2019/dsa-4435","https://www.debian.org/security/2019/dsa-4448","https://www.debian.org/security/2019/dsa-4451","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://openjdk.org/groups/vulnerability/advisories/2019-07-16","https://www.mozilla.org/en-US/security/advisories/mfsa2019-13","https://www.mozilla.org/en-US/security/advisories/mfsa2019-14","https://www.mozilla.org/en-US/security/advisories/mfsa2019-15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-7317","description":"png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.4+11-1ubuntu2~18.04.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-7317","versionConstraint":"< 11.0.4+11-1ubuntu2~18.04.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-7317","fix":{"state":"fixed","versions":["11.0.4+11-1ubuntu2~18.04.3"],"available":[{"date":"2019-07-31","kind":"advisory","version":"11.0.4+11-1ubuntu2~18.04.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-7317","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-7317","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-7317","date":"2026-10-08","epss":0.09393,"percentile":0.95291}],"risk":4.6965,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-7317"},"relatedVulnerabilities":[{"id":"CVE-2019-7317","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-7317","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-7317","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-7317","date":"2026-10-08","epss":0.09393,"percentile":0.95291}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00002.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00029.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00084.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00038.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00044.html","http://packetstormsecurity.com/files/152561/Slackware-Security-Advisory-libpng-Updates.html","http://www.securityfocus.com/bid/108098","https://access.redhat.com/errata/RHSA-2019:1265","https://access.redhat.com/errata/RHSA-2019:1267","https://access.redhat.com/errata/RHSA-2019:1269","https://access.redhat.com/errata/RHSA-2019:1308","https://access.redhat.com/errata/RHSA-2019:1309","https://access.redhat.com/errata/RHSA-2019:1310","https://access.redhat.com/errata/RHSA-2019:2494","https://access.redhat.com/errata/RHSA-2019:2495","https://access.redhat.com/errata/RHSA-2019:2585","https://access.redhat.com/errata/RHSA-2019:2590","https://access.redhat.com/errata/RHSA-2019:2592","https://access.redhat.com/errata/RHSA-2019:2737","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12803","https://github.com/glennrp/libpng/issues/275","https://lists.debian.org/debian-lts-announce/2019/05/msg00032.html","https://lists.debian.org/debian-lts-announce/2019/05/msg00038.html","https://seclists.org/bugtraq/2019/Apr/30","https://seclists.org/bugtraq/2019/Apr/36","https://seclists.org/bugtraq/2019/May/56","https://seclists.org/bugtraq/2019/May/59","https://seclists.org/bugtraq/2019/May/67","https://security.gentoo.org/glsa/201908-02","https://security.netapp.com/advisory/ntap-20190719-0005/","https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03977en_us","https://usn.ubuntu.com/3962-1/","https://usn.ubuntu.com/3991-1/","https://usn.ubuntu.com/3997-1/","https://usn.ubuntu.com/4080-1/","https://usn.ubuntu.com/4083-1/","https://www.debian.org/security/2019/dsa-4435","https://www.debian.org/security/2019/dsa-4448","https://www.debian.org/security/2019/dsa-4451","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://openjdk.org/groups/vulnerability/advisories/2019-07-16","https://www.mozilla.org/en-US/security/advisories/mfsa2019-13","https://www.mozilla.org/en-US/security/advisories/mfsa2019-14","https://www.mozilla.org/en-US/security/advisories/mfsa2019-15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-7317","description":"png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-85cw-hj65-qqv9","versionConstraint":">=2.9.0,<2.9.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-85cw-hj65-qqv9","fix":{"state":"fixed","versions":["2.9.10"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16335","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-16335","date":"2026-10-08","epss":0.04958,"percentile":0.91959}],"risk":4.66052,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-16335","https://github.com/FasterXML/jackson-databind/issues/2449","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://access.redhat.com/errata/RHSA-2020:0729","https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69@%3Ccommits.tinkerpop.apache.org%3E","https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/a360b46061c91c5cad789b6c3190aef9b9f223a2b75c9c9f046fe016@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/ad0d238e97a7da5eca47a014f0f7e81f440ed6bf74a93183825e18b9@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/dc6b5cad721a4f6b3b62ed1163894941140d9d5656140fb757505ca0@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/e90c3feb21702e68a8c08afce37045adb3870f2bf8223fa403fb93fb@%3Ccommits.hbase.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20191004-0002/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/73c1c2cc76e6cdd7f3a5615cbe3207fe96e4d3db"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-85cw-hj65-qqv9","description":"Polymorphic Typing issue in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-16335","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16335","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-16335","date":"2026-10-08","epss":0.04958,"percentile":0.91959}],"urls":["https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://access.redhat.com/errata/RHSA-2020:0729","https://github.com/FasterXML/jackson-databind/issues/2449","https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69%40%3Ccommits.tinkerpop.apache.org%3E","https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1%40%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/a360b46061c91c5cad789b6c3190aef9b9f223a2b75c9c9f046fe016%40%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/ad0d238e97a7da5eca47a014f0f7e81f440ed6bf74a93183825e18b9%40%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/dc6b5cad721a4f6b3b62ed1163894941140d9d5656140fb757505ca0%40%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/e90c3feb21702e68a8c08afce37045adb3870f2bf8223fa403fb93fb%40%3Ccommits.hbase.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20191004-0002/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16335","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-fmmc-742q-jg75","versionConstraint":">=2.9.0,<2.9.10.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-fmmc-742q-jg75","fix":{"state":"fixed","versions":["2.9.10.1"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.10.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16943","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-16943","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-16943","date":"2026-10-08","epss":0.04901,"percentile":0.9187}],"risk":4.606940000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-16943","https://github.com/FasterXML/jackson-databind/issues/2478","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/5ec8d8d485c2c8ac55ea425f4cd96596ef37312532712639712ebcdd@%3Ccommits.iceberg.apache.org%3E","https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20191017-0006/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/FasterXML/jackson-databind/commit/328a0f833daf6baa443ac3b37c818a0204714b0b","https://github.com/FasterXML/jackson-databind/commit/bc67eb11a7cf57561f861ff16f879f1fceb5779f"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-fmmc-742q-jg75","description":"jackson-databind polymorphic typing issue"},"relatedVulnerabilities":[{"id":"CVE-2019-16943","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16943","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-16943","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-16943","date":"2026-10-08","epss":0.04901,"percentile":0.9187}],"urls":["https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://github.com/FasterXML/jackson-databind/issues/2478","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/5ec8d8d485c2c8ac55ea425f4cd96596ef37312532712639712ebcdd%40%3Ccommits.iceberg.apache.org%3E","https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20191017-0006/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16943","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.51"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qxf4-chvg-4r8r","versionConstraint":">=8.0.0,<8.5.51 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qxf4-chvg-4r8r","fix":{"state":"fixed","versions":["8.5.51"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"8.5.51"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1935","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1935","date":"2026-10-08","epss":0.09386,"percentile":0.95286}],"risk":4.59914,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-1935","https://lists.apache.org/thread.html/r127f76181aceffea2bd4711b03c595d0f115f63e020348fe925a916c%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743@%3Ccommits.tomee.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html","http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","https://security.netapp.com/advisory/ntap-20200327-0005/","https://www.debian.org/security/2020/dsa-4673","https://www.debian.org/security/2020/dsa-4680","https://lists.apache.org/thread.html/r441c1f30a252bf14b07396286f6abd8089ce4240e91323211f1a2d75@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r660cd379afe346f10d72c0eaa8459ccc95d83aff181671b7e9076919@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/ra5dee390ad2d60307b8362505c059cd6a726de4d146d63dfce1e05e7@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd547be0c9d821b4b1000a694b8e58ef9f5e2d66db03a31dfe77c4b18@%3Cusers.tomcat.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r80e9c8417c77d52c62809168b96912bda70ddf7748f19f8210f745b1@%3Cusers.tomcat.apache.org%3E","https://usn.ubuntu.com/4448-1/","https://lists.apache.org/thread.html/r9ce7918faf347e7aac32be930bf26c233b0b140fe37af0bb294158b6@%3Cdev.tomcat.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qxf4-chvg-4r8r","description":"Potential HTTP request smuggling in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2020-1935","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1935","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1935","date":"2026-10-08","epss":0.09386,"percentile":0.95286}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html","https://lists.apache.org/thread.html/r127f76181aceffea2bd4711b03c595d0f115f63e020348fe925a916c%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r441c1f30a252bf14b07396286f6abd8089ce4240e91323211f1a2d75%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r660cd379afe346f10d72c0eaa8459ccc95d83aff181671b7e9076919%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r80e9c8417c77d52c62809168b96912bda70ddf7748f19f8210f745b1%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r9ce7918faf347e7aac32be930bf26c233b0b140fe37af0bb294158b6%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/ra5dee390ad2d60307b8362505c059cd6a726de4d146d63dfce1e05e7%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rd547be0c9d821b4b1000a694b8e58ef9f5e2d66db03a31dfe77c4b18%40%3Cusers.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","https://security.netapp.com/advisory/ntap-20200327-0005/","https://usn.ubuntu.com/4448-1/","https://www.debian.org/security/2020/dsa-4673","https://www.debian.org/security/2020/dsa-4680","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1935","description":"In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h4rc-386g-6m85","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-h4rc-386g-6m85","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11620","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-11620","date":"2026-10-08","epss":0.0578,"percentile":0.92904}],"risk":4.5084,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-11620","https://github.com/FasterXML/jackson-databind/issues/2682","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://github.com/FasterXML/jackson-databind/commit/77040d85e3eb6710508e6445640ae1a3d5e60c22","https://security.netapp.com/advisory/ntap-20200511-0004"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h4rc-386g-6m85","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-11620","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11620","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-11620","date":"2026-10-08","epss":0.0578,"percentile":0.92904}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2682","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200511-0004/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-11620","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly)."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f3j5-rmmp-3fc5","versionConstraint":">=2.9.0,<2.9.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-f3j5-rmmp-3fc5","fix":{"state":"fixed","versions":["2.9.10"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-17267","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-17267","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-17267","date":"2026-10-08","epss":0.04628,"percentile":0.91467}],"risk":4.350320000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-17267","https://github.com/FasterXML/jackson-databind/issues/2460","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.3...jackson-databind-2.9.10","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r9d727fc681fb3828794acbefcaee31393742b4d73a29461ccd9597a8@%3Cdev.skywalking.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html","https://security.netapp.com/advisory/ntap-20191017-0006/","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/191a4cdf87b56d2ddddb77edd895ee756b7f75eb"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f3j5-rmmp-3fc5","description":"Improper Input Validation in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-17267","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-17267","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-17267","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-17267","date":"2026-10-08","epss":0.04628,"percentile":0.91467}],"urls":["https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.3...jackson-databind-2.9.10","https://github.com/FasterXML/jackson-databind/issues/2460","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r9d727fc681fb3828794acbefcaee31393742b4d73a29461ccd9597a8%40%3Cdev.skywalking.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html","https://security.netapp.com/advisory/ntap-20191017-0006/","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-17267","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5p34-5m6p-p58g","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5p34-5m6p-p58g","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9546","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-9546","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-9546","date":"2026-10-08","epss":0.04613,"percentile":0.91443}],"risk":4.33622,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-9546","https://github.com/FasterXML/jackson-databind/issues/2631","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6@%3Cissues.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097@%3Cissues.zookeeper.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://security.netapp.com/advisory/ntap-20200904-0006","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd%40%3Cissues.zookeeper.apache.org%3E"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5p34-5m6p-p58g","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-9546","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9546","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-9546","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-9546","date":"2026-10-08","epss":0.04613,"percentile":0.91443}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2631","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200904-0006/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-9546","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config)."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1551","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-1551","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.6"],"available":[{"date":"2020-05-28","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-1551","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1551","date":"2026-10-08","epss":0.14298,"percentile":0.96523}],"risk":4.2894,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1551"},"relatedVulnerabilities":[{"id":"CVE-2019-1551","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1551","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1551","date":"2026-10-08","epss":0.14298,"percentile":0.96523}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00030.html","http://packetstormsecurity.com/files/155754/Slackware-Security-Advisory-openssl-Updates.html","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=419102400a2811582a7a3d4a4e317d72e5ce0a8f","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=f1c5eea8a817075d31e43f5876993c6710238c98","https://lists.debian.org/debian-lts-announce/2022/03/msg00023.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDHOAATPWJCXRNFMJ2SASDBBNU5RJONY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXDDAOWSAIEFQNBHWYE6PPYFV4QXGMCD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVEP3LAK4JSPRXFO4QF4GG2IVXADV3SO/","https://seclists.org/bugtraq/2019/Dec/39","https://seclists.org/bugtraq/2019/Dec/46","https://security.gentoo.org/glsa/202004-10","https://security.netapp.com/advisory/ntap-20191210-0001/","https://usn.ubuntu.com/4376-1/","https://usn.ubuntu.com/4504-1/","https://www.debian.org/security/2019/dsa-4594","https://www.debian.org/security/2021/dsa-4855","https://www.openssl.org/news/secadv/20191206.txt","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.tenable.com/security/tns-2019-09","https://www.tenable.com/security/tns-2020-03","https://www.tenable.com/security/tns-2020-11","https://www.tenable.com/security/tns-2021-10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1551","description":"There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t)."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-1551","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-1551","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.6"],"available":[{"date":"2020-05-28","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-1551","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1551","date":"2026-10-08","epss":0.14298,"percentile":0.96523}],"risk":4.2894,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1551"},"relatedVulnerabilities":[{"id":"CVE-2019-1551","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1551","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1551","date":"2026-10-08","epss":0.14298,"percentile":0.96523}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00030.html","http://packetstormsecurity.com/files/155754/Slackware-Security-Advisory-openssl-Updates.html","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=419102400a2811582a7a3d4a4e317d72e5ce0a8f","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=f1c5eea8a817075d31e43f5876993c6710238c98","https://lists.debian.org/debian-lts-announce/2022/03/msg00023.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDHOAATPWJCXRNFMJ2SASDBBNU5RJONY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXDDAOWSAIEFQNBHWYE6PPYFV4QXGMCD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVEP3LAK4JSPRXFO4QF4GG2IVXADV3SO/","https://seclists.org/bugtraq/2019/Dec/39","https://seclists.org/bugtraq/2019/Dec/46","https://security.gentoo.org/glsa/202004-10","https://security.netapp.com/advisory/ntap-20191210-0001/","https://usn.ubuntu.com/4376-1/","https://usn.ubuntu.com/4504-1/","https://www.debian.org/security/2019/dsa-4594","https://www.debian.org/security/2021/dsa-4855","https://www.openssl.org/news/secadv/20191206.txt","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.tenable.com/security/tns-2019-09","https://www.tenable.com/security/tns-2020-03","https://www.tenable.com/security/tns-2020-11","https://www.tenable.com/security/tns-2021-10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1551","description":"There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t)."}]},{"artifact":{"id":"4b6b9929752e9980","cpes":["cpe:2.3:a:org.springframework:spring-context:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_context:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-context:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_context:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-context:spring-context:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-context:spring_context:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_context:spring-context:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_context:spring_context:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-context:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_context:5.0.8.RELEASE:*:*:*:*:*:*:*"],"name":"spring-context","purl":"pkg:maven/org.springframework/spring-context@5.0.8.RELEASE","type":"java-archive","version":"5.0.8.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-context-5.0.8.RELEASE.jar","manifestName":"","pomArtifactID":"spring-context","archiveDigests":[{"value":"3a067d8990761111c9b6d1d895640be26cc1fb38","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-context-5.0.8.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.2.21.RELEASE"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g5mm-vmx4-3rg7","versionConstraint":"<5.2.21.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-context","version":"5.0.8.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-g5mm-vmx4-3rg7","fix":{"state":"fixed","versions":["5.2.21.RELEASE"],"available":[{"date":"2024-05-16","kind":"first-observed","version":"5.2.21.RELEASE"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22968","cwe":"CWE-178","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22968","date":"2026-10-08","epss":0.05666,"percentile":0.92782}],"risk":4.2495,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22968","https://tanzu.vmware.com/security/cve-2022-22968","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/spring-projects/spring-framework/commit/833e750175349ab4fd502109a8b41af77e25cdea","https://github.com/spring-projects/spring-framework/commit/a7cf19cec5ebd270f97a194d749e2d5701ad2ab7","https://security.netapp.com/advisory/ntap-20220602-0004"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g5mm-vmx4-3rg7","description":"Improper handling of case sensitivity in Spring Framework"},"relatedVulnerabilities":[{"id":"CVE-2022-22968","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22968","cwe":"CWE-178","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22968","date":"2026-10-08","epss":0.05666,"percentile":0.92782}],"urls":["https://security.netapp.com/advisory/ntap-20220602-0004/","https://tanzu.vmware.com/security/cve-2022-22968","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22968","description":"In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35556","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35556","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-35556","cwe":"CWE-693","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-35556","date":"2026-10-08","epss":0.08464,"percentile":0.94888}],"risk":4.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35556"},"relatedVulnerabilities":[{"id":"CVE-2021-35556","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-35556","cwe":"CWE-693","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-35556","date":"2026-10-08","epss":0.08464,"percentile":0.94888}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WTVCIVHTX3XONYOEGUMLKCM4QEC6INT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DJILEHYV2U37HKMGFEQ7CAVOV4DUWW2O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V362B2BWTH5IJDL45QPQGMBKIQOG7JX5/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-5000","https://www.debian.org/security/2021/dsa-5012","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35556","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cf6r-3wgc-h863","versionConstraint":">=2.9.0,<2.9.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cf6r-3wgc-h863","fix":{"state":"fixed","versions":["2.9.10"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14892","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14892","cwe":"CWE-502","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14892","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14892","date":"2026-10-08","epss":0.05622,"percentile":0.92743}],"risk":4.2165,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-14892","https://github.com/FasterXML/jackson-databind/issues/2462","https://github.com/FasterXML/jackson-databind/commit/41b7f9b90149e9d44a65a8261a8deedc7186f6af","https://github.com/FasterXML/jackson-databind/commit/819cdbcab51c6da9fb896380f2d46e9b7d4fdc3b","https://access.redhat.com/errata/RHSA-2020:0729","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14892","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://security.netapp.com/advisory/ntap-20200904-0005/"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cf6r-3wgc-h863","description":"Polymorphic deserialization of malicious object in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-14892","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14892","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14892","cwe":"CWE-502","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14892","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14892","date":"2026-10-08","epss":0.05622,"percentile":0.92743}],"urls":["https://access.redhat.com/errata/RHSA-2020:0729","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14892","https://github.com/FasterXML/jackson-databind/issues/2462","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://security.netapp.com/advisory/ntap-20200904-0005/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-14892","description":"A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21293","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21293","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21293","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21293","date":"2026-10-08","epss":0.08346,"percentile":0.94825}],"risk":4.173,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21293"},"relatedVulnerabilities":[{"id":"CVE-2022-21293","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21293","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21293","date":"2026-10-08","epss":0.08346,"percentile":0.94825}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2DIN3L6L3SVZK75CKW2GPSU4HIGZR7XG/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21293","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-0391","versionConstraint":"< 2.7.17-1~18.04ubuntu1.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-0391","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.7"],"available":[{"date":"2022-03-28","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"risk":4.1625000000000005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-0391"},"relatedVulnerabilities":[{"id":"CVE-2022-0391","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"urls":["https://bugs.python.org/issue43882","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U/","https://security.gentoo.org/glsa/202305-02","https://security.netapp.com/advisory/ntap-20220225-0009/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0391","description":"A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\\r' and '\\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-0391","versionConstraint":"< 2.7.17-1~18.04ubuntu1.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-0391","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.7"],"available":[{"date":"2022-03-28","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"risk":4.1625000000000005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-0391"},"relatedVulnerabilities":[{"id":"CVE-2022-0391","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"urls":["https://bugs.python.org/issue43882","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U/","https://security.gentoo.org/glsa/202305-02","https://security.netapp.com/advisory/ntap-20220225-0009/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0391","description":"A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\\r' and '\\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-0391","versionConstraint":"< 2.7.17-1~18.04ubuntu1.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-0391","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.7"],"available":[{"date":"2022-03-28","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"risk":4.1625000000000005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-0391"},"relatedVulnerabilities":[{"id":"CVE-2022-0391","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"urls":["https://bugs.python.org/issue43882","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U/","https://security.gentoo.org/glsa/202305-02","https://security.netapp.com/advisory/ntap-20220225-0009/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0391","description":"A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\\r' and '\\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-0391","versionConstraint":"< 2.7.17-1~18.04ubuntu1.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-0391","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.7"],"available":[{"date":"2022-03-28","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"risk":4.1625000000000005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-0391"},"relatedVulnerabilities":[{"id":"CVE-2022-0391","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"urls":["https://bugs.python.org/issue43882","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U/","https://security.gentoo.org/glsa/202305-02","https://security.netapp.com/advisory/ntap-20220225-0009/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0391","description":"A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\\r' and '\\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14."}]},{"artifact":{"id":"351b1aea243afdc0","cpes":["cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-2:libsasl2_2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_2:libsasl2-2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_2:libsasl2_2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2-2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2_2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*"],"name":"libsasl2-2","purl":"pkg:deb/ubuntu/libsasl2-2@2.1.27~101-g0780600%2Bdfsg-3ubuntu2?arch=amd64&distro=ubuntu-18.04&upstream=cyrus-sasl2","type":"deb","version":"2.1.27~101-g0780600+dfsg-3ubuntu2","language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsasl2-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsasl2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsasl2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.27~101-g0780600+dfsg-3ubuntu2.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-19906","versionConstraint":"< 2.1.27~101-g0780600+dfsg-3ubuntu2.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"cyrus-sasl2","version":"2.1.27~101-g0780600+dfsg-3ubuntu2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-19906","fix":{"state":"fixed","versions":["2.1.27~101-g0780600+dfsg-3ubuntu2.1"],"available":[{"date":"2020-01-28","kind":"advisory","version":"2.1.27~101-g0780600+dfsg-3ubuntu2.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-19906","cwe":"CWE-193","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-19906","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19906","date":"2026-10-08","epss":0.08036,"percentile":0.94649}],"risk":4.018,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-19906"},"relatedVulnerabilities":[{"id":"CVE-2019-19906","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-19906","cwe":"CWE-193","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-19906","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19906","date":"2026-10-08","epss":0.08036,"percentile":0.94649}],"urls":["http://seclists.org/fulldisclosure/2020/Jul/23","http://seclists.org/fulldisclosure/2020/Jul/24","http://www.openwall.com/lists/oss-security/2022/02/23/4","https://github.com/cyrusimap/cyrus-sasl/issues/587","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/12/msg00027.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MW6GZCLECGL2PBNHVNPJIX4RPVRVFR7R/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OB4GSVOJ6ESHQNT5GSV63OX5D4KPSTGT/","https://seclists.org/bugtraq/2019/Dec/42","https://support.apple.com/kb/HT211288","https://support.apple.com/kb/HT211289","https://usn.ubuntu.com/4256-1/","https://www.debian.org/security/2019/dsa-4591","https://www.openldap.org/its/index.cgi/Incoming?id=9123"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19906","description":"cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl."}]},{"artifact":{"id":"5cc56cf2074d4e4c","cpes":["cpe:2.3:a:libsasl2-modules:libsasl2-modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules:libsasl2_modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2-modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2_modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2-modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2_modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*"],"name":"libsasl2-modules","purl":"pkg:deb/ubuntu/libsasl2-modules@2.1.27~101-g0780600%2Bdfsg-3ubuntu2?arch=amd64&distro=ubuntu-18.04&upstream=cyrus-sasl2","type":"deb","version":"2.1.27~101-g0780600+dfsg-3ubuntu2","language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsasl2-modules/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsasl2-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-modules:amd64.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsasl2-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-modules:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsasl2-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.27~101-g0780600+dfsg-3ubuntu2.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-19906","versionConstraint":"< 2.1.27~101-g0780600+dfsg-3ubuntu2.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"cyrus-sasl2","version":"2.1.27~101-g0780600+dfsg-3ubuntu2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-19906","fix":{"state":"fixed","versions":["2.1.27~101-g0780600+dfsg-3ubuntu2.1"],"available":[{"date":"2020-01-28","kind":"advisory","version":"2.1.27~101-g0780600+dfsg-3ubuntu2.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-19906","cwe":"CWE-193","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-19906","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19906","date":"2026-10-08","epss":0.08036,"percentile":0.94649}],"risk":4.018,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-19906"},"relatedVulnerabilities":[{"id":"CVE-2019-19906","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-19906","cwe":"CWE-193","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-19906","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19906","date":"2026-10-08","epss":0.08036,"percentile":0.94649}],"urls":["http://seclists.org/fulldisclosure/2020/Jul/23","http://seclists.org/fulldisclosure/2020/Jul/24","http://www.openwall.com/lists/oss-security/2022/02/23/4","https://github.com/cyrusimap/cyrus-sasl/issues/587","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/12/msg00027.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MW6GZCLECGL2PBNHVNPJIX4RPVRVFR7R/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OB4GSVOJ6ESHQNT5GSV63OX5D4KPSTGT/","https://seclists.org/bugtraq/2019/Dec/42","https://support.apple.com/kb/HT211288","https://support.apple.com/kb/HT211289","https://usn.ubuntu.com/4256-1/","https://www.debian.org/security/2019/dsa-4591","https://www.openldap.org/its/index.cgi/Incoming?id=9123"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19906","description":"cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl."}]},{"artifact":{"id":"f36f1535972231e5","cpes":["cpe:2.3:a:libsasl2-modules-db:libsasl2-modules-db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules-db:libsasl2_modules_db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules_db:libsasl2-modules-db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules_db:libsasl2_modules_db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules:libsasl2-modules-db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules:libsasl2_modules_db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2-modules-db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2_modules_db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2-modules-db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2_modules_db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*"],"name":"libsasl2-modules-db","purl":"pkg:deb/ubuntu/libsasl2-modules-db@2.1.27~101-g0780600%2Bdfsg-3ubuntu2?arch=amd64&distro=ubuntu-18.04&upstream=cyrus-sasl2","type":"deb","version":"2.1.27~101-g0780600+dfsg-3ubuntu2","language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsasl2-modules-db/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsasl2-modules-db/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-modules-db:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsasl2-modules-db:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.27~101-g0780600+dfsg-3ubuntu2.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-19906","versionConstraint":"< 2.1.27~101-g0780600+dfsg-3ubuntu2.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"cyrus-sasl2","version":"2.1.27~101-g0780600+dfsg-3ubuntu2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-19906","fix":{"state":"fixed","versions":["2.1.27~101-g0780600+dfsg-3ubuntu2.1"],"available":[{"date":"2020-01-28","kind":"advisory","version":"2.1.27~101-g0780600+dfsg-3ubuntu2.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-19906","cwe":"CWE-193","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-19906","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19906","date":"2026-10-08","epss":0.08036,"percentile":0.94649}],"risk":4.018,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-19906"},"relatedVulnerabilities":[{"id":"CVE-2019-19906","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-19906","cwe":"CWE-193","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-19906","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19906","date":"2026-10-08","epss":0.08036,"percentile":0.94649}],"urls":["http://seclists.org/fulldisclosure/2020/Jul/23","http://seclists.org/fulldisclosure/2020/Jul/24","http://www.openwall.com/lists/oss-security/2022/02/23/4","https://github.com/cyrusimap/cyrus-sasl/issues/587","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/12/msg00027.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MW6GZCLECGL2PBNHVNPJIX4RPVRVFR7R/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OB4GSVOJ6ESHQNT5GSV63OX5D4KPSTGT/","https://seclists.org/bugtraq/2019/Dec/42","https://support.apple.com/kb/HT211288","https://support.apple.com/kb/HT211289","https://usn.ubuntu.com/4256-1/","https://www.debian.org/security/2019/dsa-4591","https://www.openldap.org/its/index.cgi/Incoming?id=9123"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19906","description":"cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl."}]},{"artifact":{"id":"1b0eba55ba0dcd41","cpes":["cpe:2.3:a:bzip2:bzip2:1.0.6-8.1:*:*:*:*:*:*:*"],"name":"bzip2","purl":"pkg:deb/ubuntu/bzip2@1.0.6-8.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.0.6-8.1","language":"","licenses":["bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bzip2/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/bzip2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bzip2.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/bzip2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bzip2.list","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/bzip2.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.0.6-8.1ubuntu0.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-12900","versionConstraint":"< 1.0.6-8.1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"bzip2","version":"1.0.6-8.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-12900","fix":{"state":"fixed","versions":["1.0.6-8.1ubuntu0.1"],"available":[{"date":"2019-06-26","kind":"advisory","version":"1.0.6-8.1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-12900","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-12900","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-12900","date":"2026-10-08","epss":0.07977,"percentile":0.94615}],"risk":3.9884999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-12900"},"relatedVulnerabilities":[{"id":"CVE-2019-12900","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12900","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-12900","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-12900","date":"2026-10-08","epss":0.07977,"percentile":0.94615}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00040.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00050.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00078.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00000.html","http://packetstormsecurity.com/files/153644/Slackware-Security-Advisory-bzip2-Updates.html","http://packetstormsecurity.com/files/153957/FreeBSD-Security-Advisory-FreeBSD-SA-19-18.bzip2.html","https://gitlab.com/federicomenaquintero/bzip2/commit/74de1e2e6ffc9d51ef9824db71a8ffee5962cdbc","https://lists.apache.org/thread.html/ra0adb9653c7de9539b93cc8434143b655f753b9f60580ff260becb2b%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/rce8cd8c30f60604b580ea01bebda8a671a25c9a1629f409fc24e7774%40%3Cuser.flink.apache.org%3E","https://lists.apache.org/thread.html/rda98305669476c4d90cc8527c4deda7e449019dd1fe9936b56671dd4%40%3Cuser.flink.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00021.html","https://lists.debian.org/debian-lts-announce/2019/07/msg00014.html","https://lists.debian.org/debian-lts-announce/2019/10/msg00012.html","https://lists.debian.org/debian-lts-announce/2019/10/msg00018.html","https://seclists.org/bugtraq/2019/Aug/4","https://seclists.org/bugtraq/2019/Jul/22","https://security.FreeBSD.org/advisories/FreeBSD-SA-19:18.bzip2.asc","https://support.f5.com/csp/article/K68713584?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4038-1/","https://usn.ubuntu.com/4038-2/","https://usn.ubuntu.com/4146-1/","https://usn.ubuntu.com/4146-2/","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12900","description":"BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors."}]},{"artifact":{"id":"b93a1ec1b98f71d1","cpes":["cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.6-8.1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2-1.0:libbz2_1.0:1.0.6-8.1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2-1.0:1.0.6-8.1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2_1.0:1.0.6-8.1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2-1.0:1.0.6-8.1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2_1.0:1.0.6-8.1:*:*:*:*:*:*:*"],"name":"libbz2-1.0","purl":"pkg:deb/ubuntu/libbz2-1.0@1.0.6-8.1?arch=amd64&distro=ubuntu-18.04&upstream=bzip2","type":"deb","version":"1.0.6-8.1","language":"","licenses":["bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbz2-1.0/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libbz2-1.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bzip2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.0.6-8.1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-12900","versionConstraint":"< 1.0.6-8.1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"bzip2","version":"1.0.6-8.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-12900","fix":{"state":"fixed","versions":["1.0.6-8.1ubuntu0.1"],"available":[{"date":"2019-06-26","kind":"advisory","version":"1.0.6-8.1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-12900","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-12900","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-12900","date":"2026-10-08","epss":0.07977,"percentile":0.94615}],"risk":3.9884999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-12900"},"relatedVulnerabilities":[{"id":"CVE-2019-12900","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12900","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-12900","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-12900","date":"2026-10-08","epss":0.07977,"percentile":0.94615}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00040.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00050.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00078.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00000.html","http://packetstormsecurity.com/files/153644/Slackware-Security-Advisory-bzip2-Updates.html","http://packetstormsecurity.com/files/153957/FreeBSD-Security-Advisory-FreeBSD-SA-19-18.bzip2.html","https://gitlab.com/federicomenaquintero/bzip2/commit/74de1e2e6ffc9d51ef9824db71a8ffee5962cdbc","https://lists.apache.org/thread.html/ra0adb9653c7de9539b93cc8434143b655f753b9f60580ff260becb2b%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/rce8cd8c30f60604b580ea01bebda8a671a25c9a1629f409fc24e7774%40%3Cuser.flink.apache.org%3E","https://lists.apache.org/thread.html/rda98305669476c4d90cc8527c4deda7e449019dd1fe9936b56671dd4%40%3Cuser.flink.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00021.html","https://lists.debian.org/debian-lts-announce/2019/07/msg00014.html","https://lists.debian.org/debian-lts-announce/2019/10/msg00012.html","https://lists.debian.org/debian-lts-announce/2019/10/msg00018.html","https://seclists.org/bugtraq/2019/Aug/4","https://seclists.org/bugtraq/2019/Jul/22","https://security.FreeBSD.org/advisories/FreeBSD-SA-19:18.bzip2.asc","https://support.f5.com/csp/article/K68713584?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4038-1/","https://usn.ubuntu.com/4038-2/","https://usn.ubuntu.com/4146-1/","https://usn.ubuntu.com/4146-2/","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12900","description":"BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9m6f-7xcq-8vf8","versionConstraint":">=2.7.00,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-9m6f-7xcq-8vf8","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36183","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36183","date":"2026-10-08","epss":0.04972,"percentile":0.91979}],"risk":3.87816,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36183","https://github.com/FasterXML/jackson-databind/issues/3003","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/12e23c962ffb4cf1857c5461d72ae54cc8008f29","https://security.netapp.com/advisory/ntap-20210205-0005"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9m6f-7xcq-8vf8","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36183","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36183","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36183","date":"2026-10-08","epss":0.04972,"percentile":0.91979}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/3003","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36183","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21340","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21340","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21340","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21340","date":"2026-10-08","epss":0.07748,"percentile":0.9449}],"risk":3.8739999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21340"},"relatedVulnerabilities":[{"id":"CVE-2022-21340","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21340","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21340","date":"2026-10-08","epss":0.07748,"percentile":0.9449}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21340","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9636","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9636","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9636","cwe":"CWE-173","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9636","date":"2026-10-08","epss":0.07673,"percentile":0.94445}],"risk":3.8365000000000005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9636"},"relatedVulnerabilities":[{"id":"CVE-2019-9636","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9636","cwe":"CWE-173","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9636","date":"2026-10-08","epss":0.07673,"percentile":0.94445}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.html","http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00097.html","http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00024.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://www.securityfocus.com/bid/107400","https://access.redhat.com/errata/RHBA-2019:0763","https://access.redhat.com/errata/RHBA-2019:0764","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0710","https://access.redhat.com/errata/RHSA-2019:0765","https://access.redhat.com/errata/RHSA-2019:0806","https://access.redhat.com/errata/RHSA-2019:0902","https://access.redhat.com/errata/RHSA-2019:0981","https://access.redhat.com/errata/RHSA-2019:0997","https://access.redhat.com/errata/RHSA-2019:1467","https://access.redhat.com/errata/RHSA-2019:2980","https://access.redhat.com/errata/RHSA-2019:3170","https://bugs.python.org/issue36216","https://github.com/python/cpython/pull/12201","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46PVWY5LFP4BRPG3BVQ5QEEFYBVEXHCK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AEZ5IQT7OF7Q2NCGIVABOWYGKO7YU3NJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CFBAAGM27H73OLYBUA2IAZFSUN6KGLME/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D3LXPABKVLFYUHRYJPM3CSS5MS6FXKS7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ICBEGRHIPHWPG2VGYS6R4EVKVUUF4AQW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFAXBEY2TGOBDRKTR556JBXBVFSAKD6I/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMWSKTNOHSUOT3L25QFJAVCFYZX46FYK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JSKPGPZQNTAULHW4UH63KGOOUIDE4RRB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXASHCDD4PQFKTMKQN4YOP5ZH366ABN4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L25RTMKCF62DLC2XVSNXGX7C7HXISLVM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TR6GCO3WTV4D5L23WTCBF275VE6BVNI3/","https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization.html","https://security.gentoo.org/glsa/202003-26","https://security.netapp.com/advisory/ntap-20190517-0001/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9636","description":"Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9636","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9636","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9636","cwe":"CWE-173","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9636","date":"2026-10-08","epss":0.07673,"percentile":0.94445}],"risk":3.8365000000000005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9636"},"relatedVulnerabilities":[{"id":"CVE-2019-9636","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9636","cwe":"CWE-173","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9636","date":"2026-10-08","epss":0.07673,"percentile":0.94445}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.html","http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00097.html","http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00024.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://www.securityfocus.com/bid/107400","https://access.redhat.com/errata/RHBA-2019:0763","https://access.redhat.com/errata/RHBA-2019:0764","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0710","https://access.redhat.com/errata/RHSA-2019:0765","https://access.redhat.com/errata/RHSA-2019:0806","https://access.redhat.com/errata/RHSA-2019:0902","https://access.redhat.com/errata/RHSA-2019:0981","https://access.redhat.com/errata/RHSA-2019:0997","https://access.redhat.com/errata/RHSA-2019:1467","https://access.redhat.com/errata/RHSA-2019:2980","https://access.redhat.com/errata/RHSA-2019:3170","https://bugs.python.org/issue36216","https://github.com/python/cpython/pull/12201","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46PVWY5LFP4BRPG3BVQ5QEEFYBVEXHCK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AEZ5IQT7OF7Q2NCGIVABOWYGKO7YU3NJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CFBAAGM27H73OLYBUA2IAZFSUN6KGLME/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D3LXPABKVLFYUHRYJPM3CSS5MS6FXKS7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ICBEGRHIPHWPG2VGYS6R4EVKVUUF4AQW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFAXBEY2TGOBDRKTR556JBXBVFSAKD6I/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMWSKTNOHSUOT3L25QFJAVCFYZX46FYK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JSKPGPZQNTAULHW4UH63KGOOUIDE4RRB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXASHCDD4PQFKTMKQN4YOP5ZH366ABN4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L25RTMKCF62DLC2XVSNXGX7C7HXISLVM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TR6GCO3WTV4D5L23WTCBF275VE6BVNI3/","https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization.html","https://security.gentoo.org/glsa/202003-26","https://security.netapp.com/advisory/ntap-20190517-0001/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9636","description":"Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-9636","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9636","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9636","cwe":"CWE-173","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9636","date":"2026-10-08","epss":0.07673,"percentile":0.94445}],"risk":3.8365000000000005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9636"},"relatedVulnerabilities":[{"id":"CVE-2019-9636","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9636","cwe":"CWE-173","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9636","date":"2026-10-08","epss":0.07673,"percentile":0.94445}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.html","http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00097.html","http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00024.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://www.securityfocus.com/bid/107400","https://access.redhat.com/errata/RHBA-2019:0763","https://access.redhat.com/errata/RHBA-2019:0764","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0710","https://access.redhat.com/errata/RHSA-2019:0765","https://access.redhat.com/errata/RHSA-2019:0806","https://access.redhat.com/errata/RHSA-2019:0902","https://access.redhat.com/errata/RHSA-2019:0981","https://access.redhat.com/errata/RHSA-2019:0997","https://access.redhat.com/errata/RHSA-2019:1467","https://access.redhat.com/errata/RHSA-2019:2980","https://access.redhat.com/errata/RHSA-2019:3170","https://bugs.python.org/issue36216","https://github.com/python/cpython/pull/12201","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46PVWY5LFP4BRPG3BVQ5QEEFYBVEXHCK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AEZ5IQT7OF7Q2NCGIVABOWYGKO7YU3NJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CFBAAGM27H73OLYBUA2IAZFSUN6KGLME/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D3LXPABKVLFYUHRYJPM3CSS5MS6FXKS7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ICBEGRHIPHWPG2VGYS6R4EVKVUUF4AQW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFAXBEY2TGOBDRKTR556JBXBVFSAKD6I/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMWSKTNOHSUOT3L25QFJAVCFYZX46FYK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JSKPGPZQNTAULHW4UH63KGOOUIDE4RRB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXASHCDD4PQFKTMKQN4YOP5ZH366ABN4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L25RTMKCF62DLC2XVSNXGX7C7HXISLVM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TR6GCO3WTV4D5L23WTCBF275VE6BVNI3/","https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization.html","https://security.gentoo.org/glsa/202003-26","https://security.netapp.com/advisory/ntap-20190517-0001/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9636","description":"Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9636","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9636","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9636","cwe":"CWE-173","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9636","date":"2026-10-08","epss":0.07673,"percentile":0.94445}],"risk":3.8365000000000005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9636"},"relatedVulnerabilities":[{"id":"CVE-2019-9636","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9636","cwe":"CWE-173","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9636","date":"2026-10-08","epss":0.07673,"percentile":0.94445}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.html","http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00097.html","http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00024.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://www.securityfocus.com/bid/107400","https://access.redhat.com/errata/RHBA-2019:0763","https://access.redhat.com/errata/RHBA-2019:0764","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0710","https://access.redhat.com/errata/RHSA-2019:0765","https://access.redhat.com/errata/RHSA-2019:0806","https://access.redhat.com/errata/RHSA-2019:0902","https://access.redhat.com/errata/RHSA-2019:0981","https://access.redhat.com/errata/RHSA-2019:0997","https://access.redhat.com/errata/RHSA-2019:1467","https://access.redhat.com/errata/RHSA-2019:2980","https://access.redhat.com/errata/RHSA-2019:3170","https://bugs.python.org/issue36216","https://github.com/python/cpython/pull/12201","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46PVWY5LFP4BRPG3BVQ5QEEFYBVEXHCK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AEZ5IQT7OF7Q2NCGIVABOWYGKO7YU3NJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CFBAAGM27H73OLYBUA2IAZFSUN6KGLME/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D3LXPABKVLFYUHRYJPM3CSS5MS6FXKS7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ICBEGRHIPHWPG2VGYS6R4EVKVUUF4AQW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFAXBEY2TGOBDRKTR556JBXBVFSAKD6I/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMWSKTNOHSUOT3L25QFJAVCFYZX46FYK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JSKPGPZQNTAULHW4UH63KGOOUIDE4RRB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXASHCDD4PQFKTMKQN4YOP5ZH366ABN4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L25RTMKCF62DLC2XVSNXGX7C7HXISLVM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TR6GCO3WTV4D5L23WTCBF275VE6BVNI3/","https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization.html","https://security.gentoo.org/glsa/202003-26","https://security.netapp.com/advisory/ntap-20190517-0001/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9636","description":"Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9."}]},{"artifact":{"id":"0b1c74783f88c915","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.22.0-1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20506","versionConstraint":"< 3.22.0-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-20506","fix":{"state":"fixed","versions":["3.22.0-1ubuntu0.1"],"available":[{"date":"2019-06-19","kind":"advisory","version":"3.22.0-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-20506","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20506","date":"2026-10-08","epss":0.07565,"percentile":0.94378}],"risk":3.7824999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-20506"},"relatedVulnerabilities":[{"id":"CVE-2018-20506","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20506","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20506","date":"2026-10-08","epss":0.07565,"percentile":0.94378}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.html","http://seclists.org/fulldisclosure/2019/Jan/62","http://seclists.org/fulldisclosure/2019/Jan/64","http://seclists.org/fulldisclosure/2019/Jan/66","http://seclists.org/fulldisclosure/2019/Jan/67","http://seclists.org/fulldisclosure/2019/Jan/68","http://seclists.org/fulldisclosure/2019/Jan/69","http://www.securityfocus.com/bid/106698","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html","https://seclists.org/bugtraq/2019/Jan/28","https://seclists.org/bugtraq/2019/Jan/29","https://seclists.org/bugtraq/2019/Jan/31","https://seclists.org/bugtraq/2019/Jan/32","https://seclists.org/bugtraq/2019/Jan/33","https://seclists.org/bugtraq/2019/Jan/39","https://security.netapp.com/advisory/ntap-20190502-0004/","https://sqlite.org/src/info/940f2adc8541a838","https://support.apple.com/kb/HT209443","https://support.apple.com/kb/HT209446","https://support.apple.com/kb/HT209447","https://support.apple.com/kb/HT209448","https://support.apple.com/kb/HT209450","https://support.apple.com/kb/HT209451","https://usn.ubuntu.com/4019-1/","https://usn.ubuntu.com/4019-2/","https://www.oracle.com/security-alerts/cpuapr2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20506","description":"SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a \"merge\" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346."}]},{"artifact":{"id":"4f96f33b6bfa1d67","cpes":["cpe:2.3:a:thymeleaf-spring5:thymeleaf-spring5:3.0.9.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf-spring5:thymeleaf_spring5:3.0.9.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf_spring5:thymeleaf-spring5:3.0.9.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf_spring5:thymeleaf_spring5:3.0.9.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf-team:thymeleaf-spring5:3.0.9.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf-team:thymeleaf_spring5:3.0.9.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf_team:thymeleaf-spring5:3.0.9.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf_team:thymeleaf_spring5:3.0.9.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.thymeleaf:thymeleaf-spring5:3.0.9.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.thymeleaf:thymeleaf_spring5:3.0.9.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf:thymeleaf-spring5:3.0.9.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf:thymeleaf_spring5:3.0.9.RELEASE:*:*:*:*:*:*:*"],"name":"thymeleaf-spring5","purl":"pkg:maven/org.thymeleaf/thymeleaf-spring5@3.0.9.RELEASE","type":"java-archive","version":"3.0.9.RELEASE","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.thymeleaf","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/thymeleaf-spring5-3.0.9.RELEASE.jar","manifestName":"","pomArtifactID":"thymeleaf-spring5","archiveDigests":[{"value":"abf84efd83808a70d982d2790f7f3a7bd3a39cf4","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/thymeleaf-spring5-3.0.9.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13.RELEASE"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qcj6-jqrg-4wp2","versionConstraint":"<=3.0.12.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.thymeleaf:thymeleaf-spring5","version":"3.0.9.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qcj6-jqrg-4wp2","fix":{"state":"fixed","versions":["3.0.13.RELEASE"],"available":[{"date":"2022-03-15","kind":"first-observed","version":"3.0.13.RELEASE"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-43466","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-43466","date":"2026-10-08","epss":0.03993,"percentile":0.90254}],"risk":3.75342,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-43466","https://vuldb.com/?id.186365","https://github.com/thymeleaf/thymeleaf-spring/issues/263#issuecomment-977199524","https://gitee.com/wayne_wwang/wayne_wwang/blob/master/2021/10/31/ruoyi+thymeleaf-rce/index.html","https://security.netapp.com/advisory/ntap-20221014-0001/"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qcj6-jqrg-4wp2","description":"Template injection in thymeleaf-spring5"},"relatedVulnerabilities":[{"id":"CVE-2021-43466","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-43466","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-43466","date":"2026-10-08","epss":0.03993,"percentile":0.90254}],"urls":["https://gitee.com/wayne_wwang/wayne_wwang/blob/master/2021/10/31/ruoyi+thymeleaf-rce/index.html","https://security.netapp.com/advisory/ntap-20221014-0001/","https://vuldb.com/?id.186365"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-43466","description":"In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.19"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-32208","versionConstraint":"< 7.58.0-2ubuntu3.19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-32208","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.19"],"available":[{"date":"2022-06-27","kind":"advisory","version":"7.58.0-2ubuntu3.19"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-32208","cwe":"CWE-840","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32208","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32208","date":"2026-10-08","epss":0.07499,"percentile":0.94338}],"risk":3.7495000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-32208"},"relatedVulnerabilities":[{"id":"CVE-2022-32208","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-32208","cwe":"CWE-840","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32208","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32208","date":"2026-10-08","epss":0.07499,"percentile":0.94338}],"urls":["http://seclists.org/fulldisclosure/2022/Oct/28","http://seclists.org/fulldisclosure/2022/Oct/41","https://hackerone.com/reports/1590071","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20220915-0003/","https://support.apple.com/kb/HT213488","https://www.debian.org/security/2022/dsa-5197"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-32208","description":"When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.19"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-32208","versionConstraint":"< 7.58.0-2ubuntu3.19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-32208","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.19"],"available":[{"date":"2022-06-27","kind":"advisory","version":"7.58.0-2ubuntu3.19"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-32208","cwe":"CWE-840","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32208","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32208","date":"2026-10-08","epss":0.07499,"percentile":0.94338}],"risk":3.7495000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-32208"},"relatedVulnerabilities":[{"id":"CVE-2022-32208","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-32208","cwe":"CWE-840","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32208","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32208","date":"2026-10-08","epss":0.07499,"percentile":0.94338}],"urls":["http://seclists.org/fulldisclosure/2022/Oct/28","http://seclists.org/fulldisclosure/2022/Oct/41","https://hackerone.com/reports/1590071","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20220915-0003/","https://support.apple.com/kb/HT213488","https://www.debian.org/security/2022/dsa-5197"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-32208","description":"When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-5481","versionConstraint":"< 7.58.0-2ubuntu3.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-5481","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.8"],"available":[{"date":"2019-09-11","kind":"advisory","version":"7.58.0-2ubuntu3.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5481","cwe":"CWE-415","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2019-5481","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5481","date":"2026-10-08","epss":0.07465,"percentile":0.94317}],"risk":3.7325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5481"},"relatedVulnerabilities":[{"id":"CVE-2019-5481","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5481","cwe":"CWE-415","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2019-5481","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5481","date":"2026-10-08","epss":0.07465,"percentile":0.94317}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00048.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00055.html","https://curl.haxx.se/docs/CVE-2019-5481.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CI4QQ2RSZX4VCFM76SIWGKY6BY7UWIC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGDVKSLY5JUNJRLYRUA6CXGQ2LM63XC3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UA7KDM2WPM5CJDDGOEGFV6SSGD2J7RNT/","https://seclists.org/bugtraq/2020/Feb/36","https://security.gentoo.org/glsa/202003-29","https://security.netapp.com/advisory/ntap-20191004-0003/","https://www.debian.org/security/2020/dsa-4633","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5481","description":"Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-5481","versionConstraint":"< 7.58.0-2ubuntu3.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-5481","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.8"],"available":[{"date":"2019-09-11","kind":"advisory","version":"7.58.0-2ubuntu3.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5481","cwe":"CWE-415","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2019-5481","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5481","date":"2026-10-08","epss":0.07465,"percentile":0.94317}],"risk":3.7325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5481"},"relatedVulnerabilities":[{"id":"CVE-2019-5481","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5481","cwe":"CWE-415","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2019-5481","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5481","date":"2026-10-08","epss":0.07465,"percentile":0.94317}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00048.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00055.html","https://curl.haxx.se/docs/CVE-2019-5481.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CI4QQ2RSZX4VCFM76SIWGKY6BY7UWIC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGDVKSLY5JUNJRLYRUA6CXGQ2LM63XC3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UA7KDM2WPM5CJDDGOEGFV6SSGD2J7RNT/","https://seclists.org/bugtraq/2020/Feb/36","https://security.gentoo.org/glsa/202003-29","https://security.netapp.com/advisory/ntap-20191004-0003/","https://www.debian.org/security/2020/dsa-4633","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5481","description":"Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3."}]},{"artifact":{"id":"88bdd6da7cccc159","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-25235","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-25235","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-25235","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25235","cwe":"CWE-116","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25235","date":"2026-10-08","epss":0.04955,"percentile":0.91956}],"risk":3.71625,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-25235"},"relatedVulnerabilities":[{"id":"CVE-2022-25235","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25235","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25235","cwe":"CWE-116","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25235","date":"2026-10-08","epss":0.04955,"percentile":0.91956}],"urls":["http://www.openwall.com/lists/oss-security/2022/02/19/1","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/562","https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/","https://security.gentoo.org/glsa/202209-24","https://security.netapp.com/advisory/ntap-20220303-0008/","https://www.debian.org/security/2022/dsa-5085","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25235","description":"xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-23841","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-23841","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.8"],"available":[{"date":"2021-02-18","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-23841","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-23841","date":"2026-10-08","epss":0.0741,"percentile":0.94291}],"risk":3.705,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-23841"},"relatedVulnerabilities":[{"id":"CVE-2021-23841","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23841","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-23841","date":"2026-10-08","epss":0.0741,"percentile":0.94291}],"urls":["http://seclists.org/fulldisclosure/2021/May/67","http://seclists.org/fulldisclosure/2021/May/68","http://seclists.org/fulldisclosure/2021/May/70","https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=122a19ab48091c657f7cb1fb3af9fc07bd557bbf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=8252ee4d90f3f2004d3d0aeeed003ad49c9a7807","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44846","https://security.gentoo.org/glsa/202103-03","https://security.netapp.com/advisory/ntap-20210219-0009/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://support.apple.com/kb/HT212528","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212534","https://www.debian.org/security/2021/dsa-4855","https://www.openssl.org/news/secadv/20210216.txt","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-03","https://www.tenable.com/security/tns-2021-09"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23841","description":"The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x)."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-23841","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-23841","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.8"],"available":[{"date":"2021-02-18","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-23841","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-23841","date":"2026-10-08","epss":0.0741,"percentile":0.94291}],"risk":3.705,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-23841"},"relatedVulnerabilities":[{"id":"CVE-2021-23841","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23841","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-23841","date":"2026-10-08","epss":0.0741,"percentile":0.94291}],"urls":["http://seclists.org/fulldisclosure/2021/May/67","http://seclists.org/fulldisclosure/2021/May/68","http://seclists.org/fulldisclosure/2021/May/70","https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=122a19ab48091c657f7cb1fb3af9fc07bd557bbf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=8252ee4d90f3f2004d3d0aeeed003ad49c9a7807","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44846","https://security.gentoo.org/glsa/202103-03","https://security.netapp.com/advisory/ntap-20210219-0009/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://support.apple.com/kb/HT212528","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212534","https://www.debian.org/security/2021/dsa-4855","https://www.openssl.org/news/secadv/20210216.txt","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-03","https://www.tenable.com/security/tns-2021-09"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23841","description":"The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35565","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35565","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-35565","date":"2026-10-08","epss":0.07395,"percentile":0.94281}],"risk":3.6975000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35565"},"relatedVulnerabilities":[{"id":"CVE-2021-35565","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35565","date":"2026-10-08","epss":0.07395,"percentile":0.94281}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WTVCIVHTX3XONYOEGUMLKCM4QEC6INT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DJILEHYV2U37HKMGFEQ7CAVOV4DUWW2O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V362B2BWTH5IJDL45QPQGMBKIQOG7JX5/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-5000","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35565","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35550","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35550","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-35550","date":"2026-10-08","epss":0.07376,"percentile":0.94269}],"risk":3.688,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35550"},"relatedVulnerabilities":[{"id":"CVE-2021-35550","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:N/A:N","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35550","date":"2026-10-08","epss":0.07376,"percentile":0.94269}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WTVCIVHTX3XONYOEGUMLKCM4QEC6INT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DJILEHYV2U37HKMGFEQ7CAVOV4DUWW2O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V362B2BWTH5IJDL45QPQGMBKIQOG7JX5/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-5000","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35550","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.12.6.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-57j2-w4cx-62h2","versionConstraint":"<=2.12.6.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-57j2-w4cx-62h2","fix":{"state":"fixed","versions":["2.12.6.1"],"available":[{"date":"2022-03-29","kind":"first-observed","version":"2.12.6.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36518","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36518","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36518","date":"2026-10-08","epss":0.0486,"percentile":0.91812}],"risk":3.6449999999999996,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36518","https://github.com/FasterXML/jackson-databind/issues/2816","https://github.com/FasterXML/jackson-databind/commit/fcfc4998ec23f0b1f7f8a9521c2b317b6c25892b","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.12","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.13","https://lists.debian.org/debian-lts-announce/2022/05/msg00001.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","https://www.debian.org/security/2022/dsa-5283","https://github.com/FasterXML/jackson-databind/commit/0a8157c6ca478b1bc7be4ba7dccdb3863275f0de","https://github.com/FasterXML/jackson-databind/commit/3cc52f82ecf943e06c1d7c3b078e405fb3923d2b","https://github.com/FasterXML/jackson-databind/commit/8238ab41d0350fb915797c89d46777b4496b74fd","https://github.com/FasterXML/jackson-databind/commit/b3587924ee5d8695942f364d0d404d48d0ea6126","https://security.netapp.com/advisory/ntap-20220506-0004"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-57j2-w4cx-62h2","description":"Deeply nested json in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36518","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36518","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36518","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36518","date":"2026-10-08","epss":0.0486,"percentile":0.91812}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2816","https://lists.debian.org/debian-lts-announce/2022/05/msg00001.html","https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","https://security.netapp.com/advisory/ntap-20220506-0004/","https://www.debian.org/security/2022/dsa-5283","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36518","description":"jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wm9w-rjj3-j356","versionConstraint":">=8.5.0,<=8.5.100 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wm9w-rjj3-j356","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-34750","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2024-34750","cwe":"CWE-755","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-34750","date":"2026-10-08","epss":0.04602,"percentile":0.91424}],"risk":3.58956,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-34750","https://lists.apache.org/thread/4kqf0bc9gxymjc2x7v3p7dvplnl77y8l","https://github.com/apache/tomcat/commit/2344a4c0d03e307ba6b8ab6dc8b894cc8bac63f2","https://github.com/apache/tomcat/commit/2afae300c9ac9c0e516e2e9de580847d925365c3","https://github.com/apache/tomcat/commit/9fec9a82887853402833a80b584e3762c7423f5f","https://tomcat.apache.org/security-10.html","https://tomcat.apache.org/security-11.html","https://tomcat.apache.org/security-9.html","https://security.netapp.com/advisory/ntap-20240816-0004","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wm9w-rjj3-j356","description":"Apache Tomcat - Denial of Service"},"relatedVulnerabilities":[{"id":"CVE-2024-34750","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-34750","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2024-34750","cwe":"CWE-755","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-34750","date":"2026-10-08","epss":0.04602,"percentile":0.91424}],"urls":["https://lists.apache.org/thread/4kqf0bc9gxymjc2x7v3p7dvplnl77y8l","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html","https://security.netapp.com/advisory/ntap-20240816-0004/","https://github.com/apache/tomcat/commit/2344a4c0d03e307ba6b8ab6dc8b894cc8bac63f2","https://github.com/apache/tomcat/commit/2afae300c9ac9c0e516e2e9de580847d925365c3","https://github.com/apache/tomcat/commit/9fec9a82887853402833a80b584e3762c7423f5f"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-34750","description":"Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.0-M1 through 9.0.89.\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 though 8.5.100. Other EOL versions may also be affected.\n\n\nUsers are recommended to upgrade to version 11.0.0-M21, 10.1.25 or 9.0.90, which fixes the issue."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mc6h-4qgp-37qh","versionConstraint":">=2.9.0,<=2.9.10.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mc6h-4qgp-37qh","fix":{"state":"fixed","versions":["2.9.10.5"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14195","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14195","date":"2026-10-08","epss":0.04549,"percentile":0.91338}],"risk":3.5482200000000006,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-14195","https://github.com/FasterXML/jackson-databind/issues/2765","https://github.com/FasterXML/jackson-databind/commit/f6d9c664f6d481703138319f6a0f1fdbddb3a259","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://security.netapp.com/advisory/ntap-20200702-0003"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mc6h-4qgp-37qh","description":"Deserialization of untrusted data in Jackson Databind"},"relatedVulnerabilities":[{"id":"CVE-2020-14195","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14195","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14195","date":"2026-10-08","epss":0.04549,"percentile":0.91338}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2765","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://security.netapp.com/advisory/ntap-20200702-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14195","description":"FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity)."}]},{"artifact":{"id":"685ff832fa5df143","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-11236","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-11236","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-08","epss":0.07051,"percentile":0.9404}],"risk":3.5255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-11236"},"relatedVulnerabilities":[{"id":"CVE-2018-11236","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-08","epss":0.07051,"percentile":0.9404}],"urls":["http://www.securityfocus.com/bid/104255","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=22786","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=5460617d1567657621107d895ee2dd83bc1f88f2","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-11236","description":"stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution."}]},{"artifact":{"id":"71315b6fa75a7166","cpes":["cpe:2.3:a:libc6:libc6:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-11236","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-11236","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-08","epss":0.07051,"percentile":0.9404}],"risk":3.5255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-11236"},"relatedVulnerabilities":[{"id":"CVE-2018-11236","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-08","epss":0.07051,"percentile":0.9404}],"urls":["http://www.securityfocus.com/bid/104255","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=22786","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=5460617d1567657621107d895ee2dd83bc1f88f2","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-11236","description":"stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution."}]},{"artifact":{"id":"62a0389fd254614a","cpes":["cpe:2.3:a:locales:locales:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.27-3ubuntu1?arch=all&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-11236","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-11236","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-08","epss":0.07051,"percentile":0.9404}],"risk":3.5255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-11236"},"relatedVulnerabilities":[{"id":"CVE-2018-11236","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-08","epss":0.07051,"percentile":0.9404}],"urls":["http://www.securityfocus.com/bid/104255","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=22786","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=5460617d1567657621107d895ee2dd83bc1f88f2","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-11236","description":"stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution."}]},{"artifact":{"id":"6c475aa8af85f1cd","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-11236","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-11236","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-08","epss":0.07051,"percentile":0.9404}],"risk":3.5255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-11236"},"relatedVulnerabilities":[{"id":"CVE-2018-11236","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-08","epss":0.07051,"percentile":0.9404}],"urls":["http://www.securityfocus.com/bid/104255","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=22786","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=5460617d1567657621107d895ee2dd83bc1f88f2","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-11236","description":"stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution."}]},{"artifact":{"id":"0b1c74783f88c915","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.22.0-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-19926","versionConstraint":"< 3.22.0-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-19926","fix":{"state":"fixed","versions":["3.22.0-1ubuntu0.3"],"available":[{"date":"2020-03-10","kind":"advisory","version":"3.22.0-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-19926","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19926","date":"2026-10-08","epss":0.06997,"percentile":0.94002}],"risk":3.4985000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-19926"},"relatedVulnerabilities":[{"id":"CVE-2019-19926","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-19926","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19926","date":"2026-10-08","epss":0.06997,"percentile":0.94002}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00010.html","http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00015.html","http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00025.html","https://access.redhat.com/errata/RHSA-2020:0514","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://github.com/sqlite/sqlite/commit/8428b3b437569338a9d1e10c4cd8154acbe33089","https://security.netapp.com/advisory/ntap-20200114-0003/","https://usn.ubuntu.com/4298-1/","https://usn.ubuntu.com/4298-2/","https://www.debian.org/security/2020/dsa-4638","https://www.oracle.com/security-alerts/cpuapr2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19926","description":"multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c2q3-4qrh-fm48","versionConstraint":">=2.9.0,<=2.9.10.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c2q3-4qrh-fm48","fix":{"state":"fixed","versions":["2.9.10.5"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14061","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14061","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-14061","date":"2026-10-08","epss":0.04458,"percentile":0.91186}],"risk":3.47724,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-14061","https://github.com/FasterXML/jackson-databind/issues/2698","https://github.com/FasterXML/jackson-databind/commit/5c8642aeae9c756b438ab7637c90ef3c77966e6e","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://security.netapp.com/advisory/ntap-20200702-0003/","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c2q3-4qrh-fm48","description":"Deserialization of untrusted data in Jackson Databind"},"relatedVulnerabilities":[{"id":"CVE-2020-14061","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14061","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14061","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-14061","date":"2026-10-08","epss":0.04458,"percentile":0.91186}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2698","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200702-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14061","description":"FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35561","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35561","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-35561","date":"2026-10-08","epss":0.06946,"percentile":0.93954}],"risk":3.473,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35561"},"relatedVulnerabilities":[{"id":"CVE-2021-35561","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35561","date":"2026-10-08","epss":0.06946,"percentile":0.93954}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WTVCIVHTX3XONYOEGUMLKCM4QEC6INT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DJILEHYV2U37HKMGFEQ7CAVOV4DUWW2O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V362B2BWTH5IJDL45QPQGMBKIQOG7JX5/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://www.debian.org/security/2021/dsa-5000","https://www.debian.org/security/2021/dsa-5012","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35561","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Utility). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"0b1c74783f88c915","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.22.0-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-19923","versionConstraint":"< 3.22.0-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-19923","fix":{"state":"fixed","versions":["3.22.0-1ubuntu0.3"],"available":[{"date":"2020-03-10","kind":"advisory","version":"3.22.0-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-19923","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19923","date":"2026-10-08","epss":0.0681,"percentile":0.9385}],"risk":3.405,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-19923"},"relatedVulnerabilities":[{"id":"CVE-2019-19923","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-19923","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19923","date":"2026-10-08","epss":0.0681,"percentile":0.9385}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00010.html","http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00015.html","http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00025.html","https://access.redhat.com/errata/RHSA-2020:0514","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://github.com/sqlite/sqlite/commit/396afe6f6aa90a31303c183e11b2b2d4b7956b35","https://security.netapp.com/advisory/ntap-20200114-0003/","https://usn.ubuntu.com/4298-1/","https://www.debian.org/security/2020/dsa-4638","https://www.oracle.com/security-alerts/cpuapr2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19923","description":"flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results)."}]},{"artifact":{"id":"0b1c74783f88c915","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.22.0-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-19925","versionConstraint":"< 3.22.0-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-19925","fix":{"state":"fixed","versions":["3.22.0-1ubuntu0.3"],"available":[{"date":"2020-03-10","kind":"advisory","version":"3.22.0-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-19925","cwe":"CWE-434","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19925","date":"2026-10-08","epss":0.0681,"percentile":0.9385}],"risk":3.405,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-19925"},"relatedVulnerabilities":[{"id":"CVE-2019-19925","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-19925","cwe":"CWE-434","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19925","date":"2026-10-08","epss":0.0681,"percentile":0.9385}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00010.html","http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00015.html","http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00025.html","https://access.redhat.com/errata/RHSA-2020:0514","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://github.com/sqlite/sqlite/commit/54d501092d88c0cf89bec4279951f548fb0b8618","https://security.netapp.com/advisory/ntap-20200114-0003/","https://usn.ubuntu.com/4298-1/","https://www.debian.org/security/2020/dsa-4638","https://www.oracle.com/security-alerts/cpuapr2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19925","description":"zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive."}]},{"artifact":{"id":"91ad4ea54a8353ff","cpes":["cpe:2.3:a:perl-base:perl-base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.26.1-6ubuntu0.3?arch=amd64&distro=ubuntu-18.04&upstream=perl","type":"deb","version":"5.26.1-6ubuntu0.3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.26.1-6ubuntu0.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-10543","versionConstraint":"< 5.26.1-6ubuntu0.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"perl","version":"5.26.1-6ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-10543","fix":{"state":"fixed","versions":["5.26.1-6ubuntu0.5"],"available":[{"date":"2020-10-26","kind":"advisory","version":"5.26.1-6ubuntu0.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-10543","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10543","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10543","date":"2026-10-08","epss":0.11334,"percentile":0.95884}],"risk":3.4002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-10543"},"relatedVulnerabilities":[{"id":"CVE-2020-10543","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:P","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10543","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10543","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10543","date":"2026-10-08","epss":0.11334,"percentile":0.95884}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.html","https://github.com/Perl/perl5/blob/blead/pod/perl5303delta.pod","https://github.com/Perl/perl5/compare/v5.30.2...v5.30.3","https://github.com/perl/perl5/commit/897d1f7fd515b828e4b198d8b8bef76c6faf03ed","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE/","https://security.gentoo.org/glsa/202006-03","https://security.netapp.com/advisory/ntap-20200611-0001/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10543","description":"Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35586","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35586","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-35586","date":"2026-10-08","epss":0.0679,"percentile":0.93832}],"risk":3.395,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35586"},"relatedVulnerabilities":[{"id":"CVE-2021-35586","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35586","date":"2026-10-08","epss":0.0679,"percentile":0.93832}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-5000","https://www.debian.org/security/2021/dsa-5012","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35586","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.93"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q3mw-pvr8-9ggc","versionConstraint":">=8.5.0,<8.5.93 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q3mw-pvr8-9ggc","fix":{"state":"fixed","versions":["8.5.93"],"available":[{"date":"2023-09-29","kind":"first-observed","version":"8.5.93"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-41080","cwe":"CWE-601","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2023-41080","date":"2026-10-08","epss":0.06047,"percentile":0.93187}],"risk":3.3560849999999998,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-41080","https://lists.apache.org/thread/71wvwprtx2j2m54fovq9zr7gbm2wow2f","https://github.com/apache/tomcat/commit/4998ad745b67edeadefe541c94ed029b53933d3b","https://github.com/apache/tomcat/commit/77c0ce2d169efa248b64b992e547aad549ec906b","https://github.com/apache/tomcat/commit/bb4624a9f3e69d495182ebfa68d7983076407a27","https://github.com/apache/tomcat/commit/e3703c9abb8fe0d5602f6ba8a8f11d4b6940815a","https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","https://www.debian.org/security/2023/dsa-5521","https://www.debian.org/security/2023/dsa-5522","https://security.netapp.com/advisory/ntap-20230921-0006"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q3mw-pvr8-9ggc","description":"Apache Tomcat Open Redirect vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2023-41080","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-41080","cwe":"CWE-601","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2023-41080","date":"2026-10-08","epss":0.06047,"percentile":0.93187}],"urls":["https://lists.apache.org/thread/71wvwprtx2j2m54fovq9zr7gbm2wow2f","https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","https://security.netapp.com/advisory/ntap-20230921-0006/","https://www.debian.org/security/2023/dsa-5521","https://www.debian.org/security/2023/dsa-5522"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-41080","description":"URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92.\nOlder, EOL versions may also be affected.\n\n\nThe vulnerability is limited to the ROOT (default) web application."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35578","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35578","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-35578","date":"2026-10-08","epss":0.06679,"percentile":0.93732}],"risk":3.3395,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35578"},"relatedVulnerabilities":[{"id":"CVE-2021-35578","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35578","date":"2026-10-08","epss":0.06679,"percentile":0.93732}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-5000","https://www.debian.org/security/2021/dsa-5012","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35578","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"88bdd6da7cccc159","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-15903","versionConstraint":"< 2.2.5-3ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-15903","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.2"],"available":[{"date":"2019-09-12","kind":"advisory","version":"2.2.5-3ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-15903","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-15903","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-15903","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-15903","date":"2026-10-08","epss":0.06643,"percentile":0.93704}],"risk":3.3215000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-15903"},"relatedVulnerabilities":[{"id":"CVE-2019-15903","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-15903","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-15903","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-15903","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-15903","date":"2026-10-08","epss":0.06643,"percentile":0.93704}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00080.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00081.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00000.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00002.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00003.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00013.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00016.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00017.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00018.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00008.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://packetstormsecurity.com/files/154503/Slackware-Security-Advisory-expat-Updates.html","http://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python-Updates.html","http://packetstormsecurity.com/files/154947/Slackware-Security-Advisory-mozilla-firefox-Updates.html","http://seclists.org/fulldisclosure/2019/Dec/23","http://seclists.org/fulldisclosure/2019/Dec/26","http://seclists.org/fulldisclosure/2019/Dec/27","http://seclists.org/fulldisclosure/2019/Dec/30","https://access.redhat.com/errata/RHSA-2019:3210","https://access.redhat.com/errata/RHSA-2019:3237","https://access.redhat.com/errata/RHSA-2019:3756","https://github.com/libexpat/libexpat/commit/c20b758c332d9a13afbbb276d30db1d183a85d43","https://github.com/libexpat/libexpat/issues/317","https://github.com/libexpat/libexpat/issues/342","https://github.com/libexpat/libexpat/pull/318","https://lists.debian.org/debian-lts-announce/2019/11/msg00006.html","https://lists.debian.org/debian-lts-announce/2019/11/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A4TZKPJFTURRLXIGLB34WVKQ5HGY6JJA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BDUTI5TVQWIGGQXPEVI4T2ENHFSBMIBP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S26LGXXQ7YF2BP3RGOWELBFKM6BHF6UG/","https://seclists.org/bugtraq/2019/Dec/17","https://seclists.org/bugtraq/2019/Dec/21","https://seclists.org/bugtraq/2019/Dec/23","https://seclists.org/bugtraq/2019/Nov/1","https://seclists.org/bugtraq/2019/Nov/24","https://seclists.org/bugtraq/2019/Oct/29","https://seclists.org/bugtraq/2019/Sep/30","https://seclists.org/bugtraq/2019/Sep/37","https://security.gentoo.org/glsa/201911-08","https://security.netapp.com/advisory/ntap-20190926-0004/","https://support.apple.com/kb/HT210785","https://support.apple.com/kb/HT210788","https://support.apple.com/kb/HT210789","https://support.apple.com/kb/HT210790","https://support.apple.com/kb/HT210793","https://support.apple.com/kb/HT210794","https://support.apple.com/kb/HT210795","https://usn.ubuntu.com/4132-1/","https://usn.ubuntu.com/4132-2/","https://usn.ubuntu.com/4165-1/","https://usn.ubuntu.com/4202-1/","https://usn.ubuntu.com/4335-1/","https://www.debian.org/security/2019/dsa-4530","https://www.debian.org/security/2019/dsa-4549","https://www.debian.org/security/2019/dsa-4571","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.tenable.com/security/tns-2021-11"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-15903","description":"In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8w26-6f25-cm9x","versionConstraint":">=2.0.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-8w26-6f25-cm9x","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36185","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36185","date":"2026-10-08","epss":0.04237,"percentile":0.9077}],"risk":3.3048599999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36185","https://github.com/FasterXML/jackson-databind/issues/2998","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/567194c53ae91f0a14dc27239afb739b1c10448a"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8w26-6f25-cm9x","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36185","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36185","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36185","date":"2026-10-08","epss":0.04237,"percentile":0.9077}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/2998","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36185","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r695-7vr9-jgc2","versionConstraint":">=2.0.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r695-7vr9-jgc2","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36187","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36187","date":"2026-10-08","epss":0.04237,"percentile":0.9077}],"risk":3.3048599999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36187","https://github.com/FasterXML/jackson-databind/issues/2997","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3e8fa3beea49ea62109df9e643c9cb678dabdde1"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r695-7vr9-jgc2","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36187","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36187","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36187","date":"2026-10-08","epss":0.04237,"percentile":0.9077}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/2997","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36187","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v585-23hc-c647","versionConstraint":">=2.0.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-v585-23hc-c647","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-11-30","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36186","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36186","date":"2026-10-08","epss":0.04237,"percentile":0.9077}],"risk":3.3048599999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36186","https://github.com/FasterXML/jackson-databind/issues/2997","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3e8fa3beea49ea62109df9e643c9cb678dabdde1"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v585-23hc-c647","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36186","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36186","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36186","date":"2026-10-08","epss":0.04237,"percentile":0.9077}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/2997","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36186","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource."}]},{"artifact":{"id":"3445236446ec4939","cpes":["cpe:2.3:a:krb5-locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5-locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"krb5-locales","purl":"pkg:deb/ubuntu/krb5-locales@1.16-2ubuntu0.1?arch=all&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/krb5-locales/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/krb5-locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/krb5-locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/krb5-locales.list"}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 1.16-2ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["1.16-2ubuntu0.3"],"available":[{"date":"2023-01-25","kind":"advisory","version":"1.16-2ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"c67e239bf70af34c","cpes":["cpe:2.3:a:libasn1-8-heimdal:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1-8-heimdal:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8_heimdal:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8_heimdal:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1-8:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1-8:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libasn1-8-heimdal","purl":"pkg:deb/ubuntu/libasn1-8-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libasn1-8-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libasn1-8-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libasn1-8-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libasn1-8-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"f3fc35a2cb3401bd","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/ubuntu/libgssapi-krb5-2@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 1.16-2ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["1.16-2ubuntu0.3"],"available":[{"date":"2023-01-25","kind":"advisory","version":"1.16-2ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"489fa43422e60874","cpes":["cpe:2.3:a:libgssapi3-heimdal:libgssapi3-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3-heimdal:libgssapi3_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3_heimdal:libgssapi3-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3_heimdal:libgssapi3_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3:libgssapi3-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3:libgssapi3_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libgssapi3-heimdal","purl":"pkg:deb/ubuntu/libgssapi3-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi3-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libgssapi3-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi3-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libgssapi3-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"8af38808136cd0ba","cpes":["cpe:2.3:a:libhcrypto4-heimdal:libhcrypto4-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4-heimdal:libhcrypto4_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4_heimdal:libhcrypto4-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4_heimdal:libhcrypto4_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4:libhcrypto4-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4:libhcrypto4_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libhcrypto4-heimdal","purl":"pkg:deb/ubuntu/libhcrypto4-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libhcrypto4-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libhcrypto4-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libhcrypto4-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libhcrypto4-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"4fe49c3e8d200f83","cpes":["cpe:2.3:a:libheimbase1-heimdal:libheimbase1-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1-heimdal:libheimbase1_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1_heimdal:libheimbase1-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1_heimdal:libheimbase1_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1:libheimbase1-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1:libheimbase1_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libheimbase1-heimdal","purl":"pkg:deb/ubuntu/libheimbase1-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheimbase1-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libheimbase1-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheimbase1-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libheimbase1-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"5ac1d9d8c3d94a69","cpes":["cpe:2.3:a:libheimntlm0-heimdal:libheimntlm0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0-heimdal:libheimntlm0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0_heimdal:libheimntlm0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0_heimdal:libheimntlm0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0:libheimntlm0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0:libheimntlm0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libheimntlm0-heimdal","purl":"pkg:deb/ubuntu/libheimntlm0-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheimntlm0-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libheimntlm0-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheimntlm0-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libheimntlm0-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"5aedfa9521e17f6a","cpes":["cpe:2.3:a:libhx509-5-heimdal:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509-5-heimdal:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5_heimdal:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5_heimdal:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509-5:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509-5:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libhx509-5-heimdal","purl":"pkg:deb/ubuntu/libhx509-5-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libhx509-5-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libhx509-5-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libhx509-5-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libhx509-5-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"ce64c2275844a0e2","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/ubuntu/libk5crypto3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 1.16-2ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["1.16-2ubuntu0.3"],"available":[{"date":"2023-01-25","kind":"advisory","version":"1.16-2ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"ec3f5f14c892446a","cpes":["cpe:2.3:a:libkrb5-26-heimdal:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-26-heimdal:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26_heimdal:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26_heimdal:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-26:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-26:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libkrb5-26-heimdal","purl":"pkg:deb/ubuntu/libkrb5-26-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-26-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libkrb5-26-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-26-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libkrb5-26-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"a0e77fe46f00e692","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/ubuntu/libkrb5-3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 1.16-2ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["1.16-2ubuntu0.3"],"available":[{"date":"2023-01-25","kind":"advisory","version":"1.16-2ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"402827dd4cb6593f","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/ubuntu/libkrb5support0@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 1.16-2ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["1.16-2ubuntu0.3"],"available":[{"date":"2023-01-25","kind":"advisory","version":"1.16-2ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"d29c0be392861a2d","cpes":["cpe:2.3:a:libroken18-heimdal:libroken18-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18-heimdal:libroken18_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18_heimdal:libroken18-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18_heimdal:libroken18_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18:libroken18-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18:libroken18_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libroken18-heimdal","purl":"pkg:deb/ubuntu/libroken18-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libroken18-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libroken18-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libroken18-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libroken18-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"4c95d1ed3ad0ede5","cpes":["cpe:2.3:a:libwind0-heimdal:libwind0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0-heimdal:libwind0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0_heimdal:libwind0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0_heimdal:libwind0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0:libwind0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0:libwind0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libwind0-heimdal","purl":"pkg:deb/ubuntu/libwind0-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwind0-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libwind0-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwind0-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libwind0-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cvm9-fjm9-3572","versionConstraint":">=2.7.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cvm9-fjm9-3572","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36181","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36181","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36181","date":"2026-10-08","epss":0.04092,"percentile":0.90468}],"risk":3.19176,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36181","https://github.com/FasterXML/jackson-databind/issues/3004","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3ded28aece694d0df39c9f0fa1ff385b14a8656b"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cvm9-fjm9-3572","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36181","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36181","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36181","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36181","date":"2026-10-08","epss":0.04092,"percentile":0.90468}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/3004","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36181","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-89qr-369f-5m5x","versionConstraint":">=2.7.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-89qr-369f-5m5x","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36182","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36182","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36182","date":"2026-10-08","epss":0.04092,"percentile":0.90467}],"risk":3.19176,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36182","https://github.com/FasterXML/jackson-databind/issues/3004","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3ded28aece694d0df39c9f0fa1ff385b14a8656b"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-89qr-369f-5m5x","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36182","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36182","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36182","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36182","date":"2026-10-08","epss":0.04092,"percentile":0.90467}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/3004","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36182","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8c4j-34r4-xr8g","versionConstraint":">=2.7.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-8c4j-34r4-xr8g","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36180","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36180","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36180","date":"2026-10-08","epss":0.04092,"percentile":0.90467}],"risk":3.19176,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36180","https://github.com/FasterXML/jackson-databind/issues/3004","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3ded28aece694d0df39c9f0fa1ff385b14a8656b"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8c4j-34r4-xr8g","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36180","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36180","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36180","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36180","date":"2026-10-08","epss":0.04092,"percentile":0.90467}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/3004","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36180","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.14"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-22924","versionConstraint":"< 7.58.0-2ubuntu3.14 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22924","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.14"],"available":[{"date":"2021-07-22","kind":"advisory","version":"7.58.0-2ubuntu3.14"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22924","cwe":"CWE-20","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22924","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22924","date":"2026-10-08","epss":0.0627,"percentile":0.93399}],"risk":3.1350000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22924"},"relatedVulnerabilities":[{"id":"CVE-2021-22924","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22924","cwe":"CWE-20","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22924","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22924","date":"2026-10-08","epss":0.0627,"percentile":0.93399}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-732250.pdf","https://hackerone.com/reports/1223565","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cusers.kafka.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/08/msg00017.html","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/","https://security.netapp.com/advisory/ntap-20210902-0003/","https://www.debian.org/security/2022/dsa-5197","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22924","description":"libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.14"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-22924","versionConstraint":"< 7.58.0-2ubuntu3.14 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22924","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.14"],"available":[{"date":"2021-07-22","kind":"advisory","version":"7.58.0-2ubuntu3.14"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22924","cwe":"CWE-20","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22924","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22924","date":"2026-10-08","epss":0.0627,"percentile":0.93399}],"risk":3.1350000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22924"},"relatedVulnerabilities":[{"id":"CVE-2021-22924","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22924","cwe":"CWE-20","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22924","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22924","date":"2026-10-08","epss":0.0627,"percentile":0.93399}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-732250.pdf","https://hackerone.com/reports/1223565","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cusers.kafka.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/08/msg00017.html","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/","https://security.netapp.com/advisory/ntap-20210902-0003/","https://www.debian.org/security/2022/dsa-5197","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22924","description":"libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.7+10-2ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-2803","versionConstraint":"< 11.0.7+10-2ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-2803","fix":{"state":"fixed","versions":["11.0.7+10-2ubuntu2~18.04"],"available":[{"date":"2020-04-22","kind":"advisory","version":"11.0.7+10-2ubuntu2~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2020-2803","date":"2026-10-08","epss":0.0623,"percentile":0.93363}],"risk":3.115,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-2803"},"relatedVulnerabilities":[{"id":"CVE-2020-2803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"impactScore":6.5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-2803","date":"2026-10-08","epss":0.0623,"percentile":0.93363}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00000.html","http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00023.html","http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00048.html","https://lists.debian.org/debian-lts-announce/2020/04/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CKAV6KFFAEANXAN73AFTGU7Z6YNRWCXQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7VHC4EW36KZEIDQ56RPCWBZCQELFFKN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NYHHHZRHXCBGRHGE5UP7UEB4IZ2QX536/","https://security.gentoo.org/glsa/202006-22","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200416-0004/","https://usn.ubuntu.com/4337-1/","https://www.debian.org/security/2020/dsa-4662","https://www.debian.org/security/2020/dsa-4668","https://www.oracle.com/security-alerts/cpuapr2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-2803","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vfqx-33qm-g869","versionConstraint":">=2.7.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-vfqx-33qm-g869","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36189","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36189","date":"2026-10-08","epss":0.03987,"percentile":0.90242}],"risk":3.1098600000000003,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36189","https://github.com/FasterXML/jackson-databind/issues/2996","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/33d96c13fe18a2dad01b19ce195548c9acea9da4"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vfqx-33qm-g869","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36189","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36189","date":"2026-10-08","epss":0.03987,"percentile":0.90242}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/2996","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36189","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource."}]},{"artifact":{"id":"81f8e17aa26e6e42","cpes":["cpe:2.3:a:org.springframework:spring-web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-web:spring-web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-web:spring_web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_web:spring-web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_web:spring_web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_web:5.0.8.RELEASE:*:*:*:*:*:*:*"],"name":"spring-web","purl":"pkg:maven/org.springframework/spring-web@5.0.8.RELEASE","type":"java-archive","version":"5.0.8.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-web-5.0.8.RELEASE.jar","manifestName":"","pomArtifactID":"spring-web","archiveDigests":[{"value":"fa43cdadb4ab2491fd1d0ddb06c0808e4b60fc85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-web-5.0.8.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-ccgv-vj62-xf9h","versionConstraint":"<=5.2.25.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-web","version":"5.0.8.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-ccgv-vj62-xf9h","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-22243","cwe":"CWE-601","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-22243","date":"2026-10-08","epss":0.03967,"percentile":0.9019}],"risk":3.09426,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-22243","https://spring.io/security/cve-2024-22243","https://github.com/spring-projects/spring-framework/blob/main/spring-web/src/main/java/org/springframework/web/util/UriComponentsBuilder.java","https://security.netapp.com/advisory/ntap-20240524-0001","http://seclists.org/fulldisclosure/2024/Sep/24"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-ccgv-vj62-xf9h","description":"Spring Web vulnerable to Open Redirect or Server Side Request Forgery"},"relatedVulnerabilities":[{"id":"CVE-2024-22243","cvss":[{"type":"Secondary","source":"security@vmware.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-22243","cwe":"CWE-601","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-22243","date":"2026-10-08","epss":0.03967,"percentile":0.9019}],"urls":["https://security.netapp.com/advisory/ntap-20240524-0001/","https://spring.io/security/cve-2024-22243","http://seclists.org/fulldisclosure/2024/Sep/24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-22243","description":"Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a  open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks."}]},{"artifact":{"id":"351b1aea243afdc0","cpes":["cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-2:libsasl2_2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_2:libsasl2-2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_2:libsasl2_2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2-2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2_2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*"],"name":"libsasl2-2","purl":"pkg:deb/ubuntu/libsasl2-2@2.1.27~101-g0780600%2Bdfsg-3ubuntu2?arch=amd64&distro=ubuntu-18.04&upstream=cyrus-sasl2","type":"deb","version":"2.1.27~101-g0780600+dfsg-3ubuntu2","language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsasl2-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsasl2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsasl2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.27~101-g0780600+dfsg-3ubuntu2.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-24407","versionConstraint":"< 2.1.27~101-g0780600+dfsg-3ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"cyrus-sasl2","version":"2.1.27~101-g0780600+dfsg-3ubuntu2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-24407","fix":{"state":"fixed","versions":["2.1.27~101-g0780600+dfsg-3ubuntu2.4"],"available":[{"date":"2022-02-22","kind":"advisory","version":"2.1.27~101-g0780600+dfsg-3ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-24407","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24407","date":"2026-10-08","epss":0.04123,"percentile":0.90534}],"risk":3.0922500000000004,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-24407"},"relatedVulnerabilities":[{"id":"CVE-2022-24407","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6.5,"impactScore":6.5,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-24407","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24407","date":"2026-10-08","epss":0.04123,"percentile":0.90534}],"urls":["http://www.openwall.com/lists/oss-security/2022/02/23/4","https://github.com/cyrusimap/cyrus-sasl/blob/fdcd13ceaef8de684dc69008011fa865c5b4a3ac/docsrc/sasl/release-notes/2.1/index.rst","https://lists.debian.org/debian-lts-announce/2022/03/msg00002.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4FIXU75Q6RBNK6UYM7MQ3TCFGXR7AX4U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H26R4SMGM3WHXX4XYNNJB4YGFIL5UNF4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZC6BMPI3V3MC2IGNLN377ETUWO7QBIH/","https://security.netapp.com/advisory/ntap-20221007-0003/","https://www.cyrusimap.org/sasl/sasl/release-notes/2.1/index.html#new-in-2-1-28","https://www.debian.org/security/2022/dsa-5087","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-24407","description":"In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement."}]},{"artifact":{"id":"5cc56cf2074d4e4c","cpes":["cpe:2.3:a:libsasl2-modules:libsasl2-modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules:libsasl2_modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2-modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2_modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2-modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2_modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*"],"name":"libsasl2-modules","purl":"pkg:deb/ubuntu/libsasl2-modules@2.1.27~101-g0780600%2Bdfsg-3ubuntu2?arch=amd64&distro=ubuntu-18.04&upstream=cyrus-sasl2","type":"deb","version":"2.1.27~101-g0780600+dfsg-3ubuntu2","language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsasl2-modules/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsasl2-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-modules:amd64.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsasl2-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-modules:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsasl2-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.27~101-g0780600+dfsg-3ubuntu2.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-24407","versionConstraint":"< 2.1.27~101-g0780600+dfsg-3ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"cyrus-sasl2","version":"2.1.27~101-g0780600+dfsg-3ubuntu2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-24407","fix":{"state":"fixed","versions":["2.1.27~101-g0780600+dfsg-3ubuntu2.4"],"available":[{"date":"2022-02-22","kind":"advisory","version":"2.1.27~101-g0780600+dfsg-3ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-24407","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24407","date":"2026-10-08","epss":0.04123,"percentile":0.90534}],"risk":3.0922500000000004,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-24407"},"relatedVulnerabilities":[{"id":"CVE-2022-24407","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6.5,"impactScore":6.5,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-24407","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24407","date":"2026-10-08","epss":0.04123,"percentile":0.90534}],"urls":["http://www.openwall.com/lists/oss-security/2022/02/23/4","https://github.com/cyrusimap/cyrus-sasl/blob/fdcd13ceaef8de684dc69008011fa865c5b4a3ac/docsrc/sasl/release-notes/2.1/index.rst","https://lists.debian.org/debian-lts-announce/2022/03/msg00002.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4FIXU75Q6RBNK6UYM7MQ3TCFGXR7AX4U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H26R4SMGM3WHXX4XYNNJB4YGFIL5UNF4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZC6BMPI3V3MC2IGNLN377ETUWO7QBIH/","https://security.netapp.com/advisory/ntap-20221007-0003/","https://www.cyrusimap.org/sasl/sasl/release-notes/2.1/index.html#new-in-2-1-28","https://www.debian.org/security/2022/dsa-5087","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-24407","description":"In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement."}]},{"artifact":{"id":"f36f1535972231e5","cpes":["cpe:2.3:a:libsasl2-modules-db:libsasl2-modules-db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules-db:libsasl2_modules_db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules_db:libsasl2-modules-db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules_db:libsasl2_modules_db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules:libsasl2-modules-db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules:libsasl2_modules_db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2-modules-db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2_modules_db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2-modules-db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2_modules_db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2:*:*:*:*:*:*:*"],"name":"libsasl2-modules-db","purl":"pkg:deb/ubuntu/libsasl2-modules-db@2.1.27~101-g0780600%2Bdfsg-3ubuntu2?arch=amd64&distro=ubuntu-18.04&upstream=cyrus-sasl2","type":"deb","version":"2.1.27~101-g0780600+dfsg-3ubuntu2","language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsasl2-modules-db/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsasl2-modules-db/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-modules-db:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsasl2-modules-db:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.27~101-g0780600+dfsg-3ubuntu2.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-24407","versionConstraint":"< 2.1.27~101-g0780600+dfsg-3ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"cyrus-sasl2","version":"2.1.27~101-g0780600+dfsg-3ubuntu2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-24407","fix":{"state":"fixed","versions":["2.1.27~101-g0780600+dfsg-3ubuntu2.4"],"available":[{"date":"2022-02-22","kind":"advisory","version":"2.1.27~101-g0780600+dfsg-3ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-24407","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24407","date":"2026-10-08","epss":0.04123,"percentile":0.90534}],"risk":3.0922500000000004,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-24407"},"relatedVulnerabilities":[{"id":"CVE-2022-24407","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6.5,"impactScore":6.5,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-24407","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24407","date":"2026-10-08","epss":0.04123,"percentile":0.90534}],"urls":["http://www.openwall.com/lists/oss-security/2022/02/23/4","https://github.com/cyrusimap/cyrus-sasl/blob/fdcd13ceaef8de684dc69008011fa865c5b4a3ac/docsrc/sasl/release-notes/2.1/index.rst","https://lists.debian.org/debian-lts-announce/2022/03/msg00002.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4FIXU75Q6RBNK6UYM7MQ3TCFGXR7AX4U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H26R4SMGM3WHXX4XYNNJB4YGFIL5UNF4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZC6BMPI3V3MC2IGNLN377ETUWO7QBIH/","https://security.netapp.com/advisory/ntap-20221007-0003/","https://www.cyrusimap.org/sasl/sasl/release-notes/2.1/index.html#new-in-2-1-28","https://www.debian.org/security/2022/dsa-5087","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-24407","description":"In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qmqc-x3r4-6v39","versionConstraint":">=2.9.0,<2.9.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qmqc-x3r4-6v39","fix":{"state":"fixed","versions":["2.9.10"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.10"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-14893","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14893","cwe":"CWE-502","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14893","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14893","date":"2026-10-08","epss":0.04091,"percentile":0.90465}],"risk":3.06825,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-14893","https://github.com/FasterXML/jackson-databind/issues/2469","https://github.com/FasterXML/jackson-databind/commit/998efd708284778f29d83d7962a9bd935c228317","https://access.redhat.com/errata/RHSA-2020:0729","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14893","https://security.netapp.com/advisory/ntap-20200327-0006/","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qmqc-x3r4-6v39","description":"Polymorphic deserialization of malicious object in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-14893","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14893","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14893","cwe":"CWE-502","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14893","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14893","date":"2026-10-08","epss":0.04091,"percentile":0.90465}],"urls":["https://access.redhat.com/errata/RHSA-2020:0729","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14893","https://github.com/FasterXML/jackson-databind/issues/2469","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://security.netapp.com/advisory/ntap-20200327-0006/","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-14893","description":"A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code."}]},{"artifact":{"id":"8c95e64e888bf916","cpes":["cpe:2.3:a:com.squareup.retrofit2:retrofit:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:retrofit2:retrofit:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:retrofit:retrofit:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:squareup:retrofit:2.1.0:*:*:*:*:*:*:*"],"name":"retrofit","purl":"pkg:maven/com.squareup.retrofit2/retrofit@2.1.0","type":"java-archive","version":"2.1.0","language":"java","licenses":[],"metadata":{"pomGroupID":"com.squareup.retrofit2","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/retrofit-2.1.0.jar","manifestName":"","pomArtifactID":"retrofit","archiveDigests":[{"value":"2de7cd8b95b7021b1d597f049bcb422055119f2c","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/retrofit-2.1.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.5.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8p8g-f9vg-r7xr","versionConstraint":">=2.0.0,<2.5.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.squareup.retrofit2:retrofit","version":"2.1.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-8p8g-f9vg-r7xr","fix":{"state":"fixed","versions":["2.5.0"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.5.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000850","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000850","date":"2026-10-08","epss":0.04033,"percentile":0.90341}],"risk":3.0247499999999996,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-1000850","https://github.com/square/retrofit/commit/b9a7f6ad72073ddd40254c0058710e87a073047d#diff-943ec7ed35e68201824904d1dc0ec982","https://access.redhat.com/errata/RHSA-2019:3892","https://github.com/square/retrofit/blob/master/CHANGELOG.md","https://ihacktoprotect.com/post/retrofit-path-traversal/","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8p8g-f9vg-r7xr","description":"Directory Traversal vulnerability in Square Retrofit"},"relatedVulnerabilities":[{"id":"CVE-2018-1000850","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:P","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000850","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000850","date":"2026-10-08","epss":0.04033,"percentile":0.90341}],"urls":["https://access.redhat.com/errata/RHSA-2019:3892","https://github.com/square/retrofit/blob/master/CHANGELOG.md","https://github.com/square/retrofit/commit/b9a7f6ad72073ddd40254c0058710e87a073047d#diff-943ec7ed35e68201824904d1dc0ec982","https://ihacktoprotect.com/post/retrofit-path-traversal/","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000850","description":"Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to her.. This attack appear to be exploitable via An attacker should have access to an encoded path parameter on POST, PUT or DELETE request.. This vulnerability appears to have been fixed in 2.5.0 and later."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.94"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r6j3-px5g-cq3x","versionConstraint":">=8.5.0,<8.5.94 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r6j3-px5g-cq3x","fix":{"state":"fixed","versions":["8.5.94"],"available":[{"date":"2023-12-22","kind":"first-observed","version":"8.5.94"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45648","cwe":"CWE-20","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2023-45648","cwe":"NVD-CWE-Other","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-45648","date":"2026-10-08","epss":0.05848,"percentile":0.92995}],"risk":3.01172,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-45648","https://lists.apache.org/thread/2pv8yz1pyp088tsxfb7ogltk9msk0jdp","http://www.openwall.com/lists/oss-security/2023/10/10/10","https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","https://www.debian.org/security/2023/dsa-5521","https://www.debian.org/security/2023/dsa-5522","https://github.com/apache/tomcat/commit/59583245639d8c42ae0009f4a4a70464d3ea70a0","https://github.com/apache/tomcat/commit/8ecff306507be8e4fd3adee1ae5de1ea6661a8f4","https://github.com/apache/tomcat/commit/eb5c094e5560764cda436362254997511a3ca1f6","https://github.com/apache/tomcat/commit/c83fe47725f7ae9ae213568d9039171124fb7ec6","https://security.netapp.com/advisory/ntap-20231103-0007"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r6j3-px5g-cq3x","description":"Apache Tomcat Improper Input Validation vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2023-45648","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45648","cwe":"CWE-20","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2023-45648","cwe":"NVD-CWE-Other","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-45648","date":"2026-10-08","epss":0.05848,"percentile":0.92995}],"urls":["https://lists.apache.org/thread/2pv8yz1pyp088tsxfb7ogltk9msk0jdp","http://www.openwall.com/lists/oss-security/2023/10/10/10","https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","https://security.netapp.com/advisory/ntap-20231103-0007/","https://www.debian.org/security/2023/dsa-5521","https://www.debian.org/security/2023/dsa-5522"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45648","description":"Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially \ncrafted, invalid trailer header could cause Tomcat to treat a single \nrequest as multiple requests leading to the possibility of request \nsmuggling when behind a reverse proxy.\n\nOlder, EOL versions may also be affected.\n\n\nUsers are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45447","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2026-45447","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"risk":3.0015,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45447"},"relatedVulnerabilities":[{"id":"CVE-2026-45447","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"urls":["https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c","https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8","https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54","https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c","https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e","https://openssl-library.org/news/secadv/20260609.txt","https://access.redhat.com/errata/RHSA-2026:25237","https://access.redhat.com/errata/RHSA-2026:25239","https://access.redhat.com/errata/RHSA-2026:26275","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:34102","https://access.redhat.com/errata/RHSA-2026:35869","https://access.redhat.com/errata/RHSA-2026:36215","https://access.redhat.com/errata/RHSA-2026:36217","https://access.redhat.com/errata/RHSA-2026:39009","https://access.redhat.com/errata/RHSA-2026:39012","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:44438","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:58563","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:66524","https://access.redhat.com/security/cve/CVE-2026-45447","https://bugzilla.redhat.com/show_bug.cgi?id=2481898","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45447","description":"Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-45447","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2026-45447","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"risk":3.0015,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45447"},"relatedVulnerabilities":[{"id":"CVE-2026-45447","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"urls":["https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c","https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8","https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54","https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c","https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e","https://openssl-library.org/news/secadv/20260609.txt","https://access.redhat.com/errata/RHSA-2026:25237","https://access.redhat.com/errata/RHSA-2026:25239","https://access.redhat.com/errata/RHSA-2026:26275","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:34102","https://access.redhat.com/errata/RHSA-2026:35869","https://access.redhat.com/errata/RHSA-2026:36215","https://access.redhat.com/errata/RHSA-2026:36217","https://access.redhat.com/errata/RHSA-2026:39009","https://access.redhat.com/errata/RHSA-2026:39012","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:44438","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:58563","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:66524","https://access.redhat.com/security/cve/CVE-2026-45447","https://bugzilla.redhat.com/show_bug.cgi?id=2481898","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45447","description":"Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-58pp-9c76-5625","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-58pp-9c76-5625","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11112","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-11112","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-11112","date":"2026-10-08","epss":0.03643,"percentile":0.89274}],"risk":2.969045,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-11112","https://github.com/FasterXML/jackson-databind/issues/2666","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-58pp-9c76-5625","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-11112","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11112","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-11112","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-11112","date":"2026-10-08","epss":0.03643,"percentile":0.89274}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2666","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-11112","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy)."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rf6r-2c4q-2vwg","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-rf6r-2c4q-2vwg","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10968","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10968","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10968","date":"2026-10-08","epss":0.03626,"percentile":0.89225}],"risk":2.9551900000000004,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-10968","https://github.com/FasterXML/jackson-databind/issues/2662","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/05d7e0e13f43e12db6a51726df12c8b4d8040676","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://security.netapp.com/advisory/ntap-20200403-0002"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rf6r-2c4q-2vwg","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-10968","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10968","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10968","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10968","date":"2026-10-08","epss":0.03626,"percentile":0.89225}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2662","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10968","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy)."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v3xw-c963-f5hc","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-v3xw-c963-f5hc","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11111","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-11111","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-11111","date":"2026-10-08","epss":0.03576,"percentile":0.89083}],"risk":2.91444,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-11111","https://github.com/FasterXML/jackson-databind/issues/2664","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v3xw-c963-f5hc","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-11111","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11111","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-11111","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-11111","date":"2026-10-08","epss":0.03576,"percentile":0.89083}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2664","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-11111","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms)."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-758m-v56v-grj4","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-758m-v56v-grj4","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10969","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10969","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10969","date":"2026-10-08","epss":0.0356,"percentile":0.89017}],"risk":2.9014,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-10969","https://github.com/FasterXML/jackson-databind/issues/2642","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/6ba48457984943df0de92c54144f7dcae01b1221","https://security.netapp.com/advisory/ntap-20200403-0002"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-758m-v56v-grj4","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-10969","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10969","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10969","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10969","date":"2026-10-08","epss":0.0356,"percentile":0.89017}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2642","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10969","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-27xj-rqx5-2255","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-27xj-rqx5-2255","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11619","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-11619","date":"2026-10-08","epss":0.03714,"percentile":0.89476}],"risk":2.89692,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-11619","https://github.com/FasterXML/jackson-databind/issues/2680","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200511-0004"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-27xj-rqx5-2255","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-11619","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11619","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-11619","date":"2026-10-08","epss":0.03714,"percentile":0.89476}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2680","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200511-0004/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-11619","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35564","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35564","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-35564","date":"2026-10-08","epss":0.0563,"percentile":0.92749}],"risk":2.815,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35564"},"relatedVulnerabilities":[{"id":"CVE-2021-35564","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35564","date":"2026-10-08","epss":0.0563,"percentile":0.92749}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WTVCIVHTX3XONYOEGUMLKCM4QEC6INT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DJILEHYV2U37HKMGFEQ7CAVOV4DUWW2O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V362B2BWTH5IJDL45QPQGMBKIQOG7JX5/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-5000","https://www.debian.org/security/2021/dsa-5012","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35564","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Keytool). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"e61be9668443503c","cpes":["cpe:2.3:a:com.google.guava:guava:20.0:*:*:*:*:*:*:*","cpe:2.3:a:google:guava:20.0:*:*:*:*:*:*:*","cpe:2.3:a:guava:guava:20.0:*:*:*:*:*:*:*"],"name":"guava","purl":"pkg:maven/com.google.guava/guava@20.0","type":"java-archive","version":"20.0","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.google.guava","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/guava-20.0.jar","manifestName":"","pomArtifactID":"guava","archiveDigests":[{"value":"89507701249388e1ed5ddcf8c41f4ce1be7831ef","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/guava-20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"24.1.1-android"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mvr2-9pj6-7w5j","versionConstraint":">=11.0,<24.1.1-android (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.google.guava:guava","version":"20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mvr2-9pj6-7w5j","fix":{"state":"fixed","versions":["24.1.1-android"],"available":[{"date":"2023-11-10","kind":"first-observed","version":"24.1.1-android"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-10237","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-10237","date":"2026-10-08","epss":0.05086,"percentile":0.92131}],"risk":2.7718700000000003,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-10237","https://github.com/google/guava/wiki/CVE-2018-10237","https://groups.google.com/d/topic/guava-announce/xqWALw4W1vs/discussion","http://www.securitytracker.com/id/1041707","https://access.redhat.com/errata/RHSA-2018:2423","https://access.redhat.com/errata/RHSA-2018:2424","https://access.redhat.com/errata/RHSA-2018:2425","https://access.redhat.com/errata/RHSA-2018:2428","https://access.redhat.com/errata/RHSA-2018:2598","https://access.redhat.com/errata/RHSA-2018:2643","https://access.redhat.com/errata/RHSA-2018:2740","https://access.redhat.com/errata/RHSA-2018:2741","https://access.redhat.com/errata/RHSA-2018:2742","https://access.redhat.com/errata/RHSA-2018:2743","https://access.redhat.com/errata/RHSA-2018:2927","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3149","https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272@%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/19fa48533bc7ea1accf6b12746a74ed888ae6e49a5cf81ae4f807495@%3Ccommon-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/33c6bccfeb7adf644d4d79894ca8f09370be6ed4b20632c2e228d085@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/3d5dbdd92ac9ceaef90e40f78599f9109f2f345252e0ac9d98e7e084@%3Cgitbox.activemq.apache.org%3E","https://lists.apache.org/thread.html/3ddd79c801edd99c0978e83dbe2168ebd36fd42acfa5dac38fb03dd6@%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/cc48fe770c45a74dc3b37ed0817393e0c96701fc49bc431ed922f3cc@%3Chdfs-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r27eb79a87a760335226dbfa6a7b7bffea539a535f8e80c41e482106d@%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/r2ea4e5e5aa8ad73b001a466c582899620961f47d77a40af712c1fdf9@%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/r38e2ab87528d3c904e7fac496e8fd766b9277656ff95b97d6b6b6dcd@%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/r43491b25b2e5c368c34b106a82eff910a5cea3e90de82ad75cc16540@%3Cdev.syncope.apache.org%3E","https://lists.apache.org/thread.html/r95799427b335807a4c54776908125c3e66597b65845ae50096d9278a@%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/ra0adb9653c7de9539b93cc8434143b655f753b9f60580ff260becb2b@%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/rc78f6e84f82cc662860e96526d8ab969f34dbe12dc560e22d9d147a3@%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/rc8467f357b943ceaa86f289f8bc1a5d1c7955b75d3bac1426f2d4ac1@%3Ccommon-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rd0c8ec6e044aa2958dd0549ebf8ecead7f5968c9474ba73a504161b2@%3Cdev.cxf.apache.org%3E","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r02e39d7beb32eebcdbb4b516e95f67d71c90d5d462b26f4078d21eeb@%3Cdev.flink.apache.org%3E","https://lists.apache.org/thread.html/r02e39d7beb32eebcdbb4b516e95f67d71c90d5d462b26f4078d21eeb@%3Cuser.flink.apache.org%3E","https://lists.apache.org/thread.html/r223bc776a077d0795786c38cbc6e7dd808fce1a9161b00ba9c0a5d55@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/r50fc0bcc734dd82e691d36d209258683141bfc0083739a77e56ad92d@%3Cdev.flink.apache.org%3E","https://lists.apache.org/thread.html/ra4f44016926dcb034b3b230280a18102062f94ae55b8a31bb92fed84@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/ra8906723927aef2a599398c238eacfc845b74d812e0093ec2fc70a7d@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/rb3da574c34bc6bd37972d2266af3093b90d7e437460423c24f477919@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/rdc56c15693c236e31e1e95f847b8e5e74fc0a05741d47488e7fc8c45@%3Cissues.flink.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://lists.apache.org/thread.html/r841c5e14e1b55281523ebcde661ece00b38a0569e00ef5e12bd5f6ba@%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r22c8173b804cd4a420c43064ba4e363d0022aa421008b1989f7354d4@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r30e7d7b6bfa630dacc41649a0e96dad75165d50474c1241068aa0f94@%3Cissues.storm.apache.org%3E","https://lists.apache.org/thread.html/r352e40ca9874d1beb4ad95403792adca7eb295e6bc3bd7b65fabcc21@%3Ccommits.samza.apache.org%3E","https://lists.apache.org/thread.html/r3c3b33ee5bef0c67391d27a97cbfd89d44f328cf072b601b58d4e748@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rd01f5ff0164c468ec7abc96ff7646cea3cce6378da2e4aa29c6bcb95@%3Cgithub.arrow.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2021.html","https://security.netapp.com/advisory/ntap-20220629-0008/"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mvr2-9pj6-7w5j","description":"Denial of Service in Google Guava"},"relatedVulnerabilities":[{"id":"CVE-2018-10237","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-10237","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-10237","date":"2026-10-08","epss":0.05086,"percentile":0.92131}],"urls":["http://www.securitytracker.com/id/1041707","https://access.redhat.com/errata/RHSA-2018:2423","https://access.redhat.com/errata/RHSA-2018:2424","https://access.redhat.com/errata/RHSA-2018:2425","https://access.redhat.com/errata/RHSA-2018:2428","https://access.redhat.com/errata/RHSA-2018:2598","https://access.redhat.com/errata/RHSA-2018:2643","https://access.redhat.com/errata/RHSA-2018:2740","https://access.redhat.com/errata/RHSA-2018:2741","https://access.redhat.com/errata/RHSA-2018:2742","https://access.redhat.com/errata/RHSA-2018:2743","https://access.redhat.com/errata/RHSA-2018:2927","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3149","https://groups.google.com/d/topic/guava-announce/xqWALw4W1vs/discussion","https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/19fa48533bc7ea1accf6b12746a74ed888ae6e49a5cf81ae4f807495%40%3Ccommon-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/33c6bccfeb7adf644d4d79894ca8f09370be6ed4b20632c2e228d085%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/3d5dbdd92ac9ceaef90e40f78599f9109f2f345252e0ac9d98e7e084%40%3Cgitbox.activemq.apache.org%3E","https://lists.apache.org/thread.html/3ddd79c801edd99c0978e83dbe2168ebd36fd42acfa5dac38fb03dd6%40%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/cc48fe770c45a74dc3b37ed0817393e0c96701fc49bc431ed922f3cc%40%3Chdfs-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r02e39d7beb32eebcdbb4b516e95f67d71c90d5d462b26f4078d21eeb%40%3Cdev.flink.apache.org%3E","https://lists.apache.org/thread.html/r02e39d7beb32eebcdbb4b516e95f67d71c90d5d462b26f4078d21eeb%40%3Cuser.flink.apache.org%3E","https://lists.apache.org/thread.html/r223bc776a077d0795786c38cbc6e7dd808fce1a9161b00ba9c0a5d55%40%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/r22c8173b804cd4a420c43064ba4e363d0022aa421008b1989f7354d4%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r27eb79a87a760335226dbfa6a7b7bffea539a535f8e80c41e482106d%40%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/r2ea4e5e5aa8ad73b001a466c582899620961f47d77a40af712c1fdf9%40%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/r30e7d7b6bfa630dacc41649a0e96dad75165d50474c1241068aa0f94%40%3Cissues.storm.apache.org%3E","https://lists.apache.org/thread.html/r352e40ca9874d1beb4ad95403792adca7eb295e6bc3bd7b65fabcc21%40%3Ccommits.samza.apache.org%3E","https://lists.apache.org/thread.html/r38e2ab87528d3c904e7fac496e8fd766b9277656ff95b97d6b6b6dcd%40%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/r3c3b33ee5bef0c67391d27a97cbfd89d44f328cf072b601b58d4e748%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r43491b25b2e5c368c34b106a82eff910a5cea3e90de82ad75cc16540%40%3Cdev.syncope.apache.org%3E","https://lists.apache.org/thread.html/r50fc0bcc734dd82e691d36d209258683141bfc0083739a77e56ad92d%40%3Cdev.flink.apache.org%3E","https://lists.apache.org/thread.html/r841c5e14e1b55281523ebcde661ece00b38a0569e00ef5e12bd5f6ba%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r95799427b335807a4c54776908125c3e66597b65845ae50096d9278a%40%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/ra0adb9653c7de9539b93cc8434143b655f753b9f60580ff260becb2b%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/ra4f44016926dcb034b3b230280a18102062f94ae55b8a31bb92fed84%40%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/ra8906723927aef2a599398c238eacfc845b74d812e0093ec2fc70a7d%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/rb3da574c34bc6bd37972d2266af3093b90d7e437460423c24f477919%40%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/rc78f6e84f82cc662860e96526d8ab969f34dbe12dc560e22d9d147a3%40%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/rc8467f357b943ceaa86f289f8bc1a5d1c7955b75d3bac1426f2d4ac1%40%3Ccommon-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rd01f5ff0164c468ec7abc96ff7646cea3cce6378da2e4aa29c6bcb95%40%3Cgithub.arrow.apache.org%3E","https://lists.apache.org/thread.html/rd0c8ec6e044aa2958dd0549ebf8ecead7f5968c9474ba73a504161b2%40%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/rdc56c15693c236e31e1e95f847b8e5e74fc0a05741d47488e7fc8c45%40%3Cissues.flink.apache.org%3E","https://security.netapp.com/advisory/ntap-20220629-0008/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10237","description":"Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable."}]},{"artifact":{"id":"685ff832fa5df143","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19591","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-19591","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-19591","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-19591","cwe":"CWE-404","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-19591","date":"2026-10-08","epss":0.05532,"percentile":0.92616}],"risk":2.766,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19591"},"relatedVulnerabilities":[{"id":"CVE-2018-19591","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19591","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-19591","cwe":"CWE-404","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-19591","date":"2026-10-08","epss":0.05532,"percentile":0.92616}],"urls":["http://www.securityfocus.com/bid/106037","http://www.securitytracker.com/id/1042174","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO7WHN52GFMC5F2I2232GFIPSSXWFV7G/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M52KE4YR3GNMHQUOS3DKAGZD5TQ5D5UH/","https://security.gentoo.org/glsa/201903-09","https://security.gentoo.org/glsa/201908-06","https://security.netapp.com/advisory/ntap-20190321-0003/","https://sourceware.org/bugzilla/show_bug.cgi?id=23927","https://sourceware.org/git/?p=glibc.git%3Ba=blob_plain%3Bf=NEWS%3Bhb=HEAD","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=d527c860f5a3f0ed687bd03f0cb464612dc23408","https://usn.ubuntu.com/4416-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19591","description":"In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function."}]},{"artifact":{"id":"71315b6fa75a7166","cpes":["cpe:2.3:a:libc6:libc6:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19591","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-19591","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-19591","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-19591","cwe":"CWE-404","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-19591","date":"2026-10-08","epss":0.05532,"percentile":0.92616}],"risk":2.766,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19591"},"relatedVulnerabilities":[{"id":"CVE-2018-19591","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19591","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-19591","cwe":"CWE-404","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-19591","date":"2026-10-08","epss":0.05532,"percentile":0.92616}],"urls":["http://www.securityfocus.com/bid/106037","http://www.securitytracker.com/id/1042174","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO7WHN52GFMC5F2I2232GFIPSSXWFV7G/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M52KE4YR3GNMHQUOS3DKAGZD5TQ5D5UH/","https://security.gentoo.org/glsa/201903-09","https://security.gentoo.org/glsa/201908-06","https://security.netapp.com/advisory/ntap-20190321-0003/","https://sourceware.org/bugzilla/show_bug.cgi?id=23927","https://sourceware.org/git/?p=glibc.git%3Ba=blob_plain%3Bf=NEWS%3Bhb=HEAD","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=d527c860f5a3f0ed687bd03f0cb464612dc23408","https://usn.ubuntu.com/4416-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19591","description":"In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function."}]},{"artifact":{"id":"62a0389fd254614a","cpes":["cpe:2.3:a:locales:locales:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.27-3ubuntu1?arch=all&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19591","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-19591","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-19591","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-19591","cwe":"CWE-404","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-19591","date":"2026-10-08","epss":0.05532,"percentile":0.92616}],"risk":2.766,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19591"},"relatedVulnerabilities":[{"id":"CVE-2018-19591","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19591","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-19591","cwe":"CWE-404","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-19591","date":"2026-10-08","epss":0.05532,"percentile":0.92616}],"urls":["http://www.securityfocus.com/bid/106037","http://www.securitytracker.com/id/1042174","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO7WHN52GFMC5F2I2232GFIPSSXWFV7G/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M52KE4YR3GNMHQUOS3DKAGZD5TQ5D5UH/","https://security.gentoo.org/glsa/201903-09","https://security.gentoo.org/glsa/201908-06","https://security.netapp.com/advisory/ntap-20190321-0003/","https://sourceware.org/bugzilla/show_bug.cgi?id=23927","https://sourceware.org/git/?p=glibc.git%3Ba=blob_plain%3Bf=NEWS%3Bhb=HEAD","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=d527c860f5a3f0ed687bd03f0cb464612dc23408","https://usn.ubuntu.com/4416-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19591","description":"In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function."}]},{"artifact":{"id":"6c475aa8af85f1cd","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19591","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-19591","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-19591","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-19591","cwe":"CWE-404","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-19591","date":"2026-10-08","epss":0.05532,"percentile":0.92616}],"risk":2.766,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19591"},"relatedVulnerabilities":[{"id":"CVE-2018-19591","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19591","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-19591","cwe":"CWE-404","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-19591","date":"2026-10-08","epss":0.05532,"percentile":0.92616}],"urls":["http://www.securityfocus.com/bid/106037","http://www.securitytracker.com/id/1042174","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO7WHN52GFMC5F2I2232GFIPSSXWFV7G/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M52KE4YR3GNMHQUOS3DKAGZD5TQ5D5UH/","https://security.gentoo.org/glsa/201903-09","https://security.gentoo.org/glsa/201908-06","https://security.netapp.com/advisory/ntap-20190321-0003/","https://sourceware.org/bugzilla/show_bug.cgi?id=23927","https://sourceware.org/git/?p=glibc.git%3Ba=blob_plain%3Bf=NEWS%3Bhb=HEAD","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=d527c860f5a3f0ed687bd03f0cb464612dc23408","https://usn.ubuntu.com/4416-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19591","description":"In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function."}]},{"artifact":{"id":"aba67f9ad28b889b","cpes":["cpe:2.3:a:com.fasterxml.jackson.datatype.jackson-datatype-jsr310:jackson-datatype-jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.datatype.jackson-datatype-jsr310:jackson_datatype_jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.datatype.jackson-datatype-jsr310:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.datatype:jackson-datatype-jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.datatype:jackson_datatype_jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.module:jackson-datatype-jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.module:jackson_datatype_jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-datatype-jsr310:jackson-datatype-jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-datatype-jsr310:jackson_datatype_jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_datatype_jsr310:jackson-datatype-jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_datatype_jsr310:jackson_datatype_jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-datatype:jackson-datatype-jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-datatype:jackson_datatype_jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_datatype:jackson-datatype-jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_datatype:jackson_datatype_jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.datatype:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.module:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-datatype-jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_datatype_jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:datatype:jackson-datatype-jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:datatype:jackson_datatype_jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-datatype-jsr310:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-datatype-jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_datatype_jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_datatype_jsr310:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:module:jackson-datatype-jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:module:jackson_datatype_jsr310:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-datatype:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_datatype:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:datatype:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:module:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-datatype-jsr310","purl":"pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.datatype","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-datatype-jsr310-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-datatype-jsr310","archiveDigests":[{"value":"ea54f6193d224e5e5732bbd4262327eb465397c2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-datatype-jsr310-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h4x4-5qp2-wp46","versionConstraint":"<2.9.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.datatype:jackson-datatype-jsr310","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-h4x4-5qp2-wp46","fix":{"state":"fixed","versions":["2.9.8"],"available":[{"date":"2020-09-12","kind":"first-observed","version":"2.9.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000873","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000873","date":"2026-10-08","epss":0.04758,"percentile":0.91661}],"risk":2.7358499999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-1000873","https://github.com/FasterXML/jackson-modules-java8/issues/90","https://github.com/FasterXML/jackson-modules-java8/pull/87","https://bugzilla.redhat.com/show_bug.cgi?id=1665601","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://security.netapp.com/advisory/ntap-20200904-0004/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h4x4-5qp2-wp46","description":"Moderate severity vulnerability that affects com.fasterxml.jackson.datatype:jackson-datatype-jsr353"},"relatedVulnerabilities":[{"id":"CVE-2018-1000873","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000873","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000873","date":"2026-10-08","epss":0.04758,"percentile":0.91661}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1665601","https://github.com/FasterXML/jackson-modules-java8/issues/90","https://github.com/FasterXML/jackson-modules-java8/pull/87","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://security.netapp.com/advisory/ntap-20200904-0004/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000873","description":"Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rpr3-cw39-3pxh","versionConstraint":"<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-rpr3-cw39-3pxh","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2022-07-16","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10650","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10650","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10650","date":"2026-10-08","epss":0.03471,"percentile":0.88752}],"risk":2.7073799999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-10650","https://github.com/FasterXML/jackson-databind/issues/2658","https://github.com/luisgarciacheckmarx/LGV_onefile/issues/19","https://github.com/FasterXML/jackson-databind/pull/2864","https://github.com/FasterXML/jackson-databind/commit/a424c038ba0c0d65e579e22001dec925902ac0ef","https://www.oracle.com/security-alerts/cpujan2021.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://www.oracle.com/security-alerts/cpuoct2022.html","https://lists.debian.org/debian-lts-announce/2023/04/msg00032.html","https://security.netapp.com/advisory/ntap-20230818-0007"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rpr3-cw39-3pxh","description":"jackson-databind vulnerable to unsafe deserialization"},"relatedVulnerabilities":[{"id":"CVE-2020-10650","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10650","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10650","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10650","date":"2026-10-08","epss":0.03471,"percentile":0.88752}],"urls":["https://github.com/FasterXML/jackson-databind/commit/a424c038ba0c0d65e579e22001dec925902ac0ef","https://github.com/FasterXML/jackson-databind/issues/2658","https://github.com/advisories/GHSA-rpr3-cw39-3pxh","https://lists.debian.org/debian-lts-announce/2023/04/msg00032.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20230818-0007/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10650","description":"A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9740","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9740","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9740","cwe":"CWE-93","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9740","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9740","date":"2026-10-08","epss":0.05408,"percentile":0.92485}],"risk":2.704,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9740"},"relatedVulnerabilities":[{"id":"CVE-2019-9740","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9740","cwe":"CWE-93","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9740","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9740","date":"2026-10-08","epss":0.05408,"percentile":0.92485}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00041.html","http://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python-Updates.html","http://www.openwall.com/lists/oss-security/2021/02/04/2","http://www.securityfocus.com/bid/107466","https://access.redhat.com/errata/RHSA-2019:1260","https://access.redhat.com/errata/RHSA-2019:2030","https://access.redhat.com/errata/RHSA-2019:3335","https://access.redhat.com/errata/RHSA-2019:3520","https://access.redhat.com/errata/RHSA-2019:3725","https://bugs.python.org/issue36276","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00026.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMWSKTNOHSUOT3L25QFJAVCFYZX46FYK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXASHCDD4PQFKTMKQN4YOP5ZH366ABN4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://seclists.org/bugtraq/2019/Oct/29","https://security.gentoo.org/glsa/202003-26","https://security.netapp.com/advisory/ntap-20190619-0005/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9740","description":"An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \\r\\n (specifically in the query string after a ? character) followed by an HTTP header or a Redis command. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9740","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9740","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9740","cwe":"CWE-93","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9740","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9740","date":"2026-10-08","epss":0.05408,"percentile":0.92485}],"risk":2.704,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9740"},"relatedVulnerabilities":[{"id":"CVE-2019-9740","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9740","cwe":"CWE-93","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9740","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9740","date":"2026-10-08","epss":0.05408,"percentile":0.92485}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00041.html","http://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python-Updates.html","http://www.openwall.com/lists/oss-security/2021/02/04/2","http://www.securityfocus.com/bid/107466","https://access.redhat.com/errata/RHSA-2019:1260","https://access.redhat.com/errata/RHSA-2019:2030","https://access.redhat.com/errata/RHSA-2019:3335","https://access.redhat.com/errata/RHSA-2019:3520","https://access.redhat.com/errata/RHSA-2019:3725","https://bugs.python.org/issue36276","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00026.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMWSKTNOHSUOT3L25QFJAVCFYZX46FYK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXASHCDD4PQFKTMKQN4YOP5ZH366ABN4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://seclists.org/bugtraq/2019/Oct/29","https://security.gentoo.org/glsa/202003-26","https://security.netapp.com/advisory/ntap-20190619-0005/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9740","description":"An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \\r\\n (specifically in the query string after a ? character) followed by an HTTP header or a Redis command. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-9740","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9740","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9740","cwe":"CWE-93","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9740","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9740","date":"2026-10-08","epss":0.05408,"percentile":0.92485}],"risk":2.704,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9740"},"relatedVulnerabilities":[{"id":"CVE-2019-9740","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9740","cwe":"CWE-93","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9740","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9740","date":"2026-10-08","epss":0.05408,"percentile":0.92485}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00041.html","http://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python-Updates.html","http://www.openwall.com/lists/oss-security/2021/02/04/2","http://www.securityfocus.com/bid/107466","https://access.redhat.com/errata/RHSA-2019:1260","https://access.redhat.com/errata/RHSA-2019:2030","https://access.redhat.com/errata/RHSA-2019:3335","https://access.redhat.com/errata/RHSA-2019:3520","https://access.redhat.com/errata/RHSA-2019:3725","https://bugs.python.org/issue36276","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00026.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMWSKTNOHSUOT3L25QFJAVCFYZX46FYK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXASHCDD4PQFKTMKQN4YOP5ZH366ABN4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://seclists.org/bugtraq/2019/Oct/29","https://security.gentoo.org/glsa/202003-26","https://security.netapp.com/advisory/ntap-20190619-0005/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9740","description":"An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \\r\\n (specifically in the query string after a ? character) followed by an HTTP header or a Redis command. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9740","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9740","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9740","cwe":"CWE-93","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9740","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9740","date":"2026-10-08","epss":0.05408,"percentile":0.92485}],"risk":2.704,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9740"},"relatedVulnerabilities":[{"id":"CVE-2019-9740","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9740","cwe":"CWE-93","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9740","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9740","date":"2026-10-08","epss":0.05408,"percentile":0.92485}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00041.html","http://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python-Updates.html","http://www.openwall.com/lists/oss-security/2021/02/04/2","http://www.securityfocus.com/bid/107466","https://access.redhat.com/errata/RHSA-2019:1260","https://access.redhat.com/errata/RHSA-2019:2030","https://access.redhat.com/errata/RHSA-2019:3335","https://access.redhat.com/errata/RHSA-2019:3520","https://access.redhat.com/errata/RHSA-2019:3725","https://bugs.python.org/issue36276","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00026.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMWSKTNOHSUOT3L25QFJAVCFYZX46FYK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXASHCDD4PQFKTMKQN4YOP5ZH366ABN4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://seclists.org/bugtraq/2019/Oct/29","https://security.gentoo.org/glsa/202003-26","https://security.netapp.com/advisory/ntap-20190619-0005/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9740","description":"An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \\r\\n (specifically in the query string after a ? character) followed by an HTTP header or a Redis command. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9."}]},{"artifact":{"id":"f93d61afc5c3c559","cpes":["cpe:2.3:a:org.springframework.security:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:security:5.0.7.RELEASE:*:*:*:*:*:*:*"],"name":"spring-security-web","purl":"pkg:maven/org.springframework.security/spring-security-web@5.0.7.RELEASE","type":"java-archive","version":"5.0.7.RELEASE","language":"java","licenses":[],"metadata":{"pomGroupID":"org.springframework.security","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-security-web-5.0.7.RELEASE.jar","manifestName":"","pomArtifactID":"spring-security-web","archiveDigests":[{"value":"0bab3ed579d4550bb5cc40b0a7fddd0106db7c66","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-security-web-5.0.7.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.2.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gq28-h5vg-8prx","versionConstraint":"<5.2.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework.security:spring-security-web","version":"5.0.7.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gq28-h5vg-8prx","fix":{"state":"fixed","versions":["5.2.9"],"available":[{"date":"2021-05-11","kind":"first-observed","version":"5.2.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-22112","date":"2026-10-08","epss":0.03286,"percentile":0.88127}],"risk":2.6780900000000005,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-22112","https://github.com/spring-projects/spring-security/releases/tag/5.4.4","https://tanzu.vmware.com/security/cve-2021-22112","https://www.jenkins.io/security/advisory/2021-02-19/","http://www.openwall.com/lists/oss-security/2021/02/19/7","https://lists.apache.org/thread.html/redbd004a503b3520ae5746c2ab5e93fd7da807a8c128e60d2002cd9b@%3Cissues.nifi.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://lists.apache.org/thread.html/r2cb05e499807900ba23e539643eead9c5f0652fd271f223f89da1804@%3Cpluto-scm.portals.apache.org%3E","https://lists.apache.org/thread.html/r37423ec7eea340e92a409452c35b649dce02fdc467f0b3f52086c177@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/ra6389b1b82108a3b6bbcd22979f7665fd437c2a3408c9509a15a9ca1@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r163b3e4e39803882f5be05ee8606b2b9812920e196daa2a82997ce14@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r3868207b967f926819fe3aa8d33f1666429be589bb4a62104a49f4e3@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r390783b3b1c59b978131ac08390bf77fbb3863270cbde59d5b0f5fde@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r413e380088c427f56102968df89ef2f336473e1b56b7d4b3a571a378@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r89aa1b48a827f5641310305214547f1d6b2101971a49b624737c497f@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/ra53677224fe4f04c2599abc88032076faa18dc84b329cdeba85d4cfc@%3Cpluto-scm.portals.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gq28-h5vg-8prx","description":"Privilege escalation in spring security"},"relatedVulnerabilities":[{"id":"CVE-2021-22112","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","metrics":{"baseScore":9,"impactScore":10.1,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-22112","date":"2026-10-08","epss":0.03286,"percentile":0.88127}],"urls":["http://www.openwall.com/lists/oss-security/2021/02/19/7","https://lists.apache.org/thread.html/r163b3e4e39803882f5be05ee8606b2b9812920e196daa2a82997ce14%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r2cb05e499807900ba23e539643eead9c5f0652fd271f223f89da1804%40%3Cpluto-scm.portals.apache.org%3E","https://lists.apache.org/thread.html/r37423ec7eea340e92a409452c35b649dce02fdc467f0b3f52086c177%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r3868207b967f926819fe3aa8d33f1666429be589bb4a62104a49f4e3%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r390783b3b1c59b978131ac08390bf77fbb3863270cbde59d5b0f5fde%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r413e380088c427f56102968df89ef2f336473e1b56b7d4b3a571a378%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r89aa1b48a827f5641310305214547f1d6b2101971a49b624737c497f%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/ra53677224fe4f04c2599abc88032076faa18dc84b329cdeba85d4cfc%40%3Cpluto-scm.portals.apache.org%3E","https://lists.apache.org/thread.html/ra6389b1b82108a3b6bbcd22979f7665fd437c2a3408c9509a15a9ca1%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/redbd004a503b3520ae5746c2ab5e93fd7da807a8c128e60d2002cd9b%40%3Cissues.nifi.apache.org%3E","https://tanzu.vmware.com/security/cve-2021-22112","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22112","description":"Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the application's intent is to only allow the user to run with elevated privileges in a small portion of the application, the bug can be leveraged to extend those privileges to the rest of the application."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-16890","versionConstraint":"< 7.58.0-2ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-16890","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.6"],"available":[{"date":"2019-02-06","kind":"advisory","version":"7.58.0-2ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16890","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16890","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-16890","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16890","date":"2026-10-08","epss":0.05351,"percentile":0.9243}],"risk":2.6755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16890"},"relatedVulnerabilities":[{"id":"CVE-2018-16890","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16890","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16890","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-16890","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16890","date":"2026-10-08","epss":0.05351,"percentile":0.9243}],"urls":["http://www.securityfocus.com/bid/106947","https://access.redhat.com/errata/RHSA-2019:3701","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16890","https://cert-portal.siemens.com/productcert/pdf/ssa-436177.pdf","https://curl.haxx.se/docs/CVE-2018-16890.html","https://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3E","https://security.netapp.com/advisory/ntap-20190315-0001/","https://support.f5.com/csp/article/K03314397?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/3882-1/","https://www.debian.org/security/2019/dsa-4386","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16890","description":"libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could trick libcurl to accept a bad length + offset combination that would lead to a buffer read out-of-bounds."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16890","versionConstraint":"< 7.58.0-2ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-16890","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.6"],"available":[{"date":"2019-02-06","kind":"advisory","version":"7.58.0-2ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16890","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16890","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-16890","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16890","date":"2026-10-08","epss":0.05351,"percentile":0.9243}],"risk":2.6755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16890"},"relatedVulnerabilities":[{"id":"CVE-2018-16890","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16890","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16890","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-16890","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16890","date":"2026-10-08","epss":0.05351,"percentile":0.9243}],"urls":["http://www.securityfocus.com/bid/106947","https://access.redhat.com/errata/RHSA-2019:3701","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16890","https://cert-portal.siemens.com/productcert/pdf/ssa-436177.pdf","https://curl.haxx.se/docs/CVE-2018-16890.html","https://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3E","https://security.netapp.com/advisory/ntap-20190315-0001/","https://support.f5.com/csp/article/K03314397?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/3882-1/","https://www.debian.org/security/2019/dsa-4386","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16890","description":"libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could trick libcurl to accept a bad length + offset combination that would lead to a buffer read out-of-bounds."}]},{"artifact":{"id":"839771142f972cee","cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*"],"name":"libnghttp2-14","purl":"pkg:deb/ubuntu/libnghttp2-14@1.30.0-1ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=nghttp2","type":"deb","version":"1.30.0-1ubuntu1","language":"","licenses":["BSD-2-clause","Expat","GPL-3","GPL-3+","MIT","SIL-OFL-1.1","all-permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnghttp2-14/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libnghttp2-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nghttp2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-11080","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nghttp2","version":"1.30.0-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-11080","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-11080","cwe":"CWE-707","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2020-11080","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-11080","date":"2026-10-08","epss":0.05316,"percentile":0.92393}],"risk":2.658,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-11080"},"relatedVulnerabilities":[{"id":"CVE-2020-11080","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11080","cwe":"CWE-707","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2020-11080","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-11080","date":"2026-10-08","epss":0.05316,"percentile":0.92393}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.html","https://github.com/nghttp2/nghttp2/commit/336a98feb0d56b9ac54e12736b18785c27f75090","https://github.com/nghttp2/nghttp2/commit/f8da73bd042f810f34d19f9eae02b46d870af394","https://github.com/nghttp2/nghttp2/security/advisories/GHSA-q5wr-xfw9-q7xr","https://lists.debian.org/debian-lts-announce/2021/10/msg00011.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OOYAMJVLLCLXDTHW3V5UXNULZBBK4O6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AAC2AA36OTRHKSVM5OV7TTVB3CZIGEFL/","https://www.debian.org/security/2020/dsa-4696","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-11080","description":"In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vulnerability. There is a workaround to this vulnerability. Implement nghttp2_on_frame_recv_callback callback, and if received frame is SETTINGS frame and the number of settings entries are large (e.g., > 32), then drop the connection."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-22876","versionConstraint":"< 7.58.0-2ubuntu3.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22876","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.13"],"available":[{"date":"2021-03-31","kind":"advisory","version":"7.58.0-2ubuntu3.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22876","cwe":"CWE-359","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22876","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22876","date":"2026-10-08","epss":0.05301,"percentile":0.92378}],"risk":2.6505,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22876"},"relatedVulnerabilities":[{"id":"CVE-2021-22876","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22876","cwe":"CWE-359","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22876","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22876","date":"2026-10-08","epss":0.05301,"percentile":0.92378}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://curl.se/docs/CVE-2021-22876.html","https://hackerone.com/reports/1101882","https://lists.debian.org/debian-lts-announce/2021/05/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ZC5BMIOKLBQJSFCHEDN2G2C2SH274BP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ITVWPVGLFISU5BJC2BXBRYSDXTXE2YGC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQUIOYX2KUU6FIUZVB5WWZ6JHSSYSQWJ/","https://security.gentoo.org/glsa/202105-36","https://security.netapp.com/advisory/ntap-20210521-0007/","https://www.oracle.com//security-alerts/cpujul2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22876","description":"curl 7.1.1 to and including 7.75.0 is vulnerable to an \"Exposure of Private Personal Information to an Unauthorized Actor\" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.13"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-22876","versionConstraint":"< 7.58.0-2ubuntu3.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22876","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.13"],"available":[{"date":"2021-03-31","kind":"advisory","version":"7.58.0-2ubuntu3.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22876","cwe":"CWE-359","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22876","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22876","date":"2026-10-08","epss":0.05301,"percentile":0.92378}],"risk":2.6505,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22876"},"relatedVulnerabilities":[{"id":"CVE-2021-22876","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22876","cwe":"CWE-359","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22876","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22876","date":"2026-10-08","epss":0.05301,"percentile":0.92378}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://curl.se/docs/CVE-2021-22876.html","https://hackerone.com/reports/1101882","https://lists.debian.org/debian-lts-announce/2021/05/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ZC5BMIOKLBQJSFCHEDN2G2C2SH274BP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ITVWPVGLFISU5BJC2BXBRYSDXTXE2YGC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQUIOYX2KUU6FIUZVB5WWZ6JHSSYSQWJ/","https://security.gentoo.org/glsa/202105-36","https://security.netapp.com/advisory/ntap-20210521-0007/","https://www.oracle.com//security-alerts/cpujul2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22876","description":"curl 7.1.1 to and including 7.75.0 is vulnerable to an \"Exposure of Private Personal Information to an Unauthorized Actor\" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9947","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9947","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9947","cwe":"CWE-93","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9947","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9947","date":"2026-10-08","epss":0.05253,"percentile":0.92331}],"risk":2.6265,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9947"},"relatedVulnerabilities":[{"id":"CVE-2019-9947","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9947","cwe":"CWE-93","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9947","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9947","date":"2026-10-08","epss":0.05253,"percentile":0.92331}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00062.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00063.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://www.openwall.com/lists/oss-security/2021/02/04/2","https://access.redhat.com/errata/RHSA-2019:1260","https://access.redhat.com/errata/RHSA-2019:2030","https://access.redhat.com/errata/RHSA-2019:3335","https://access.redhat.com/errata/RHSA-2019:3520","https://access.redhat.com/errata/RHSA-2019:3725","https://bugs.python.org/issue35906","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00026.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMWSKTNOHSUOT3L25QFJAVCFYZX46FYK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXASHCDD4PQFKTMKQN4YOP5ZH366ABN4/","https://security.gentoo.org/glsa/202003-26","https://security.netapp.com/advisory/ntap-20190404-0004/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9947","description":"An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \\r\\n (specifically in the path component of a URL that lacks a ? character) followed by an HTTP header or a Redis command. This is similar to the CVE-2019-9740 query string issue. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9947","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9947","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9947","cwe":"CWE-93","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9947","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9947","date":"2026-10-08","epss":0.05253,"percentile":0.92331}],"risk":2.6265,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9947"},"relatedVulnerabilities":[{"id":"CVE-2019-9947","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9947","cwe":"CWE-93","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9947","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9947","date":"2026-10-08","epss":0.05253,"percentile":0.92331}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00062.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00063.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://www.openwall.com/lists/oss-security/2021/02/04/2","https://access.redhat.com/errata/RHSA-2019:1260","https://access.redhat.com/errata/RHSA-2019:2030","https://access.redhat.com/errata/RHSA-2019:3335","https://access.redhat.com/errata/RHSA-2019:3520","https://access.redhat.com/errata/RHSA-2019:3725","https://bugs.python.org/issue35906","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00026.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMWSKTNOHSUOT3L25QFJAVCFYZX46FYK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXASHCDD4PQFKTMKQN4YOP5ZH366ABN4/","https://security.gentoo.org/glsa/202003-26","https://security.netapp.com/advisory/ntap-20190404-0004/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9947","description":"An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \\r\\n (specifically in the path component of a URL that lacks a ? character) followed by an HTTP header or a Redis command. This is similar to the CVE-2019-9740 query string issue. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-9947","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9947","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9947","cwe":"CWE-93","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9947","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9947","date":"2026-10-08","epss":0.05253,"percentile":0.92331}],"risk":2.6265,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9947"},"relatedVulnerabilities":[{"id":"CVE-2019-9947","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9947","cwe":"CWE-93","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9947","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9947","date":"2026-10-08","epss":0.05253,"percentile":0.92331}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00062.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00063.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://www.openwall.com/lists/oss-security/2021/02/04/2","https://access.redhat.com/errata/RHSA-2019:1260","https://access.redhat.com/errata/RHSA-2019:2030","https://access.redhat.com/errata/RHSA-2019:3335","https://access.redhat.com/errata/RHSA-2019:3520","https://access.redhat.com/errata/RHSA-2019:3725","https://bugs.python.org/issue35906","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00026.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMWSKTNOHSUOT3L25QFJAVCFYZX46FYK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXASHCDD4PQFKTMKQN4YOP5ZH366ABN4/","https://security.gentoo.org/glsa/202003-26","https://security.netapp.com/advisory/ntap-20190404-0004/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9947","description":"An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \\r\\n (specifically in the path component of a URL that lacks a ? character) followed by an HTTP header or a Redis command. This is similar to the CVE-2019-9740 query string issue. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9947","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9947","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9947","cwe":"CWE-93","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9947","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9947","date":"2026-10-08","epss":0.05253,"percentile":0.92331}],"risk":2.6265,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9947"},"relatedVulnerabilities":[{"id":"CVE-2019-9947","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9947","cwe":"CWE-93","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9947","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9947","date":"2026-10-08","epss":0.05253,"percentile":0.92331}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00062.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00063.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://www.openwall.com/lists/oss-security/2021/02/04/2","https://access.redhat.com/errata/RHSA-2019:1260","https://access.redhat.com/errata/RHSA-2019:2030","https://access.redhat.com/errata/RHSA-2019:3335","https://access.redhat.com/errata/RHSA-2019:3520","https://access.redhat.com/errata/RHSA-2019:3725","https://bugs.python.org/issue35906","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00026.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMWSKTNOHSUOT3L25QFJAVCFYZX46FYK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXASHCDD4PQFKTMKQN4YOP5ZH366ABN4/","https://security.gentoo.org/glsa/202003-26","https://security.netapp.com/advisory/ntap-20190404-0004/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9947","description":"An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \\r\\n (specifically in the path component of a URL that lacks a ? character) followed by an HTTP header or a Redis command. This is similar to the CVE-2019-9740 query string issue. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.12.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rgv9-q543-rqg4","versionConstraint":">=2.4.0-rc1,<2.12.7.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-rgv9-q543-rqg4","fix":{"state":"fixed","versions":["2.12.7.1"],"available":[{"date":"2022-11-16","kind":"first-observed","version":"2.12.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42004","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42004","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42004","date":"2026-10-08","epss":0.03409,"percentile":0.88544}],"risk":2.6164075,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-42004","https://github.com/FasterXML/jackson-databind/issues/3582","https://github.com/FasterXML/jackson-databind/commit/063183589218fec19a9293ed2f17ec53ea80ba88","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50490","https://security.gentoo.org/glsa/202210-21","https://www.debian.org/security/2022/dsa-5283","https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","https://github.com/FasterXML/jackson-databind/commit/35de19e7144c4df8ab178b800ba86e80c3d84252","https://github.com/FasterXML/jackson-databind/commit/cd090979b7ea78c75e4de8a4aed04f7e9fa8deea","https://security.netapp.com/advisory/ntap-20221118-0008","https://github.com/FasterXML/jackson-databind/commit/0e37a39502439ecbaa1a5b5188387c01bf7f7fa1"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rgv9-q543-rqg4","description":"Uncontrolled Resource Consumption in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2022-42004","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42004","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42004","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42004","date":"2026-10-08","epss":0.03409,"percentile":0.88544}],"urls":["https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50490","https://github.com/FasterXML/jackson-databind/commit/063183589218fec19a9293ed2f17ec53ea80ba88","https://github.com/FasterXML/jackson-databind/issues/3582","https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","https://security.gentoo.org/glsa/202210-21","https://security.netapp.com/advisory/ntap-20221118-0008/","https://www.debian.org/security/2022/dsa-5283"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42004","description":"In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-10160","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-10160","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-10160","cwe":"CWE-172","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-10160","cwe":"CWE-522","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-10160","date":"2026-10-08","epss":0.05227,"percentile":0.92305}],"risk":2.6134999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-10160"},"relatedVulnerabilities":[{"id":"CVE-2019-10160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-10160","cwe":"CWE-172","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-10160","cwe":"CWE-522","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-10160","date":"2026-10-08","epss":0.05227,"percentile":0.92305}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","https://access.redhat.com/errata/RHSA-2019:1587","https://access.redhat.com/errata/RHSA-2019:1700","https://access.redhat.com/errata/RHSA-2019:2437","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10160","https://github.com/python/cpython/commit/250b62acc59921d399f0db47db3b462cd6037e09","https://github.com/python/cpython/commit/8d0ef0b5edeae52960c7ed05ae8a12388324f87e","https://github.com/python/cpython/commit/f61599b050c621386a3fc6bc480359e2d3bb93de","https://github.com/python/cpython/commit/fd1771dbdd28709716bd531580c40ae5ed814468","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NF3DRDGMVIRYNZMSLJIHNW47HOUQYXVG/","https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization2.html","https://security.netapp.com/advisory/ntap-20190617-0003/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-10160","description":"A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-10160","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-10160","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-10160","cwe":"CWE-172","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-10160","cwe":"CWE-522","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-10160","date":"2026-10-08","epss":0.05227,"percentile":0.92305}],"risk":2.6134999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-10160"},"relatedVulnerabilities":[{"id":"CVE-2019-10160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-10160","cwe":"CWE-172","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-10160","cwe":"CWE-522","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-10160","date":"2026-10-08","epss":0.05227,"percentile":0.92305}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","https://access.redhat.com/errata/RHSA-2019:1587","https://access.redhat.com/errata/RHSA-2019:1700","https://access.redhat.com/errata/RHSA-2019:2437","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10160","https://github.com/python/cpython/commit/250b62acc59921d399f0db47db3b462cd6037e09","https://github.com/python/cpython/commit/8d0ef0b5edeae52960c7ed05ae8a12388324f87e","https://github.com/python/cpython/commit/f61599b050c621386a3fc6bc480359e2d3bb93de","https://github.com/python/cpython/commit/fd1771dbdd28709716bd531580c40ae5ed814468","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NF3DRDGMVIRYNZMSLJIHNW47HOUQYXVG/","https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization2.html","https://security.netapp.com/advisory/ntap-20190617-0003/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-10160","description":"A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-10160","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-10160","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-10160","cwe":"CWE-172","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-10160","cwe":"CWE-522","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-10160","date":"2026-10-08","epss":0.05227,"percentile":0.92305}],"risk":2.6134999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-10160"},"relatedVulnerabilities":[{"id":"CVE-2019-10160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-10160","cwe":"CWE-172","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-10160","cwe":"CWE-522","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-10160","date":"2026-10-08","epss":0.05227,"percentile":0.92305}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","https://access.redhat.com/errata/RHSA-2019:1587","https://access.redhat.com/errata/RHSA-2019:1700","https://access.redhat.com/errata/RHSA-2019:2437","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10160","https://github.com/python/cpython/commit/250b62acc59921d399f0db47db3b462cd6037e09","https://github.com/python/cpython/commit/8d0ef0b5edeae52960c7ed05ae8a12388324f87e","https://github.com/python/cpython/commit/f61599b050c621386a3fc6bc480359e2d3bb93de","https://github.com/python/cpython/commit/fd1771dbdd28709716bd531580c40ae5ed814468","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NF3DRDGMVIRYNZMSLJIHNW47HOUQYXVG/","https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization2.html","https://security.netapp.com/advisory/ntap-20190617-0003/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-10160","description":"A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-10160","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-10160","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-10160","cwe":"CWE-172","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-10160","cwe":"CWE-522","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-10160","date":"2026-10-08","epss":0.05227,"percentile":0.92305}],"risk":2.6134999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-10160"},"relatedVulnerabilities":[{"id":"CVE-2019-10160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-10160","cwe":"CWE-172","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-10160","cwe":"CWE-522","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-10160","date":"2026-10-08","epss":0.05227,"percentile":0.92305}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","https://access.redhat.com/errata/RHSA-2019:1587","https://access.redhat.com/errata/RHSA-2019:1700","https://access.redhat.com/errata/RHSA-2019:2437","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10160","https://github.com/python/cpython/commit/250b62acc59921d399f0db47db3b462cd6037e09","https://github.com/python/cpython/commit/8d0ef0b5edeae52960c7ed05ae8a12388324f87e","https://github.com/python/cpython/commit/f61599b050c621386a3fc6bc480359e2d3bb93de","https://github.com/python/cpython/commit/fd1771dbdd28709716bd531580c40ae5ed814468","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NF3DRDGMVIRYNZMSLJIHNW47HOUQYXVG/","https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization2.html","https://security.netapp.com/advisory/ntap-20190617-0003/","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-10160","description":"A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.8+10-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14562","versionConstraint":"< 11.0.8+10-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14562","fix":{"state":"fixed","versions":["11.0.8+10-0ubuntu1~18.04.1"],"available":[{"date":"2020-07-23","kind":"advisory","version":"11.0.8+10-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14562","date":"2026-10-08","epss":0.05166,"percentile":0.92227}],"risk":2.5829999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14562"},"relatedVulnerabilities":[{"id":"CVE-2020-14562","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14562","date":"2026-10-08","epss":0.05166,"percentile":0.92227}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/","https://security.gentoo.org/glsa/202008-24","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200717-0005/","https://usn.ubuntu.com/4433-1/","https://www.debian.org/security/2020/dsa-4734","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14562","description":"Vulnerability in the Java SE product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"16f6348be94c5953","cpes":["cpe:2.3:a:logback-core:logback-core:1.2.3:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.2.3:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.2.3:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.2.3:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.2.3:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.2.3:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.2.3","type":"java-archive","version":"1.2.3","language":"java","licenses":["http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/logback-core-1.2.3.jar","manifestName":"","pomArtifactID":"logback-core","archiveDigests":[{"value":"864344400c3d4d92dfeb0a305dc87d953677c03c","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/logback-core-1.2.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.2.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-668q-qrv7-99fm","versionConstraint":"<1.2.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.2.3"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-668q-qrv7-99fm","fix":{"state":"fixed","versions":["1.2.9"],"available":[{"date":"2022-03-29","kind":"first-observed","version":"1.2.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-42550","cwe":"CWE-502","type":"Secondary","source":"vulnerability@ncsc.ch"},{"cve":"CVE-2021-42550","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-42550","date":"2026-10-08","epss":0.04439,"percentile":0.91154}],"risk":2.5746199999999995,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-42550","https://github.com/cn-panda/logbackRceDemo","https://jira.qos.ch/browse/LOGBACK-1591","http://logback.qos.ch/news.html","https://github.com/qos-ch/logback/commit/87291079a1de9369ac67e20dc70a8fdc7cc4359c","https://github.com/qos-ch/logback/commit/ef4fc4186b74b45ce80d86833820106ff27edd42","https://github.com/qos-ch/logback/blob/1502cba4c1dfd135b2e715bc0cf80c0045d4d128/logback-site/src/site/pages/news.html","https://security.netapp.com/advisory/ntap-20211229-0001/","http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html","http://seclists.org/fulldisclosure/2022/Jul/11","https://cert-portal.siemens.com/productcert/pdf/ssa-371761.pdf"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-668q-qrv7-99fm","description":"Deserialization of Untrusted Data in logback"},"relatedVulnerabilities":[{"id":"CVE-2021-42550","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:C/I:C/A:C","metrics":{"baseScore":8.5,"impactScore":10.1,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-42550","cwe":"CWE-502","type":"Secondary","source":"vulnerability@ncsc.ch"},{"cve":"CVE-2021-42550","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-42550","date":"2026-10-08","epss":0.04439,"percentile":0.91154}],"urls":["http://logback.qos.ch/news.html","http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html","http://seclists.org/fulldisclosure/2022/Jul/11","https://cert-portal.siemens.com/productcert/pdf/ssa-371761.pdf","https://github.com/cn-panda/logbackRceDemo","https://jira.qos.ch/browse/LOGBACK-1591","https://security.netapp.com/advisory/ntap-20211229-0001/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-42550","description":"In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-16056","versionConstraint":"< 2.7.15-4ubuntu4~18.04.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-16056","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.2"],"available":[{"date":"2019-10-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-16056","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-16056","date":"2026-10-08","epss":0.0512,"percentile":0.9217}],"risk":2.56,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-16056"},"relatedVulnerabilities":[{"id":"CVE-2019-16056","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16056","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-16056","date":"2026-10-08","epss":0.0512,"percentile":0.9217}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00062.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00063.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00012.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00021.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","https://access.redhat.com/errata/RHSA-2019:3725","https://access.redhat.com/errata/RHSA-2019:3948","https://bugs.python.org/issue34155","https://github.com/python/cpython/commit/8cb65d1381b027f0b09ee36bfed7f35bb4dec9a9","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/09/msg00018.html","https://lists.debian.org/debian-lts-announce/2019/09/msg00019.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEARDOTXCYPYELKBD2KWZ27GSPXDI3GQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/COATURTCY7G67AYI6UDV5B2JZTBCKIDX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K4KZEFP6E4YPYB52AF4WXCUDSGQOTF37/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K7HNVIFMETMFWWWUNTB72KYJYXCZOS5V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NF3DRDGMVIRYNZMSLJIHNW47HOUQYXVG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OYGESQSGIHDCIGOBVF7VXCMIE6YDWRYB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QASRD4E2G65GGEHYKVHYCXB2XWAGTNL4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QP46PQSUKYPGWTADQ67NOV3BUN6JM34Z/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SDQQ56P7ZZR64XV5DUVWNSNXKKEXUG2J/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBTGPBUABGXZ7WH7677OEM3NSP6ZEA76/","https://security.netapp.com/advisory/ntap-20190926-0005/","https://usn.ubuntu.com/4151-1/","https://usn.ubuntu.com/4151-2/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16056","description":"An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-16056","versionConstraint":"< 2.7.15-4ubuntu4~18.04.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-16056","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.2"],"available":[{"date":"2019-10-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-16056","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-16056","date":"2026-10-08","epss":0.0512,"percentile":0.9217}],"risk":2.56,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-16056"},"relatedVulnerabilities":[{"id":"CVE-2019-16056","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16056","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-16056","date":"2026-10-08","epss":0.0512,"percentile":0.9217}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00062.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00063.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00012.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00021.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","https://access.redhat.com/errata/RHSA-2019:3725","https://access.redhat.com/errata/RHSA-2019:3948","https://bugs.python.org/issue34155","https://github.com/python/cpython/commit/8cb65d1381b027f0b09ee36bfed7f35bb4dec9a9","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/09/msg00018.html","https://lists.debian.org/debian-lts-announce/2019/09/msg00019.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEARDOTXCYPYELKBD2KWZ27GSPXDI3GQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/COATURTCY7G67AYI6UDV5B2JZTBCKIDX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K4KZEFP6E4YPYB52AF4WXCUDSGQOTF37/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K7HNVIFMETMFWWWUNTB72KYJYXCZOS5V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NF3DRDGMVIRYNZMSLJIHNW47HOUQYXVG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OYGESQSGIHDCIGOBVF7VXCMIE6YDWRYB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QASRD4E2G65GGEHYKVHYCXB2XWAGTNL4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QP46PQSUKYPGWTADQ67NOV3BUN6JM34Z/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SDQQ56P7ZZR64XV5DUVWNSNXKKEXUG2J/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBTGPBUABGXZ7WH7677OEM3NSP6ZEA76/","https://security.netapp.com/advisory/ntap-20190926-0005/","https://usn.ubuntu.com/4151-1/","https://usn.ubuntu.com/4151-2/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16056","description":"An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-16056","versionConstraint":"< 2.7.15-4ubuntu4~18.04.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-16056","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.2"],"available":[{"date":"2019-10-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-16056","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-16056","date":"2026-10-08","epss":0.0512,"percentile":0.9217}],"risk":2.56,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-16056"},"relatedVulnerabilities":[{"id":"CVE-2019-16056","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16056","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-16056","date":"2026-10-08","epss":0.0512,"percentile":0.9217}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00062.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00063.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00012.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00021.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","https://access.redhat.com/errata/RHSA-2019:3725","https://access.redhat.com/errata/RHSA-2019:3948","https://bugs.python.org/issue34155","https://github.com/python/cpython/commit/8cb65d1381b027f0b09ee36bfed7f35bb4dec9a9","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/09/msg00018.html","https://lists.debian.org/debian-lts-announce/2019/09/msg00019.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEARDOTXCYPYELKBD2KWZ27GSPXDI3GQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/COATURTCY7G67AYI6UDV5B2JZTBCKIDX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K4KZEFP6E4YPYB52AF4WXCUDSGQOTF37/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K7HNVIFMETMFWWWUNTB72KYJYXCZOS5V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NF3DRDGMVIRYNZMSLJIHNW47HOUQYXVG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OYGESQSGIHDCIGOBVF7VXCMIE6YDWRYB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QASRD4E2G65GGEHYKVHYCXB2XWAGTNL4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QP46PQSUKYPGWTADQ67NOV3BUN6JM34Z/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SDQQ56P7ZZR64XV5DUVWNSNXKKEXUG2J/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBTGPBUABGXZ7WH7677OEM3NSP6ZEA76/","https://security.netapp.com/advisory/ntap-20190926-0005/","https://usn.ubuntu.com/4151-1/","https://usn.ubuntu.com/4151-2/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16056","description":"An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-16056","versionConstraint":"< 2.7.15-4ubuntu4~18.04.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-16056","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.2"],"available":[{"date":"2019-10-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-16056","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-16056","date":"2026-10-08","epss":0.0512,"percentile":0.9217}],"risk":2.56,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-16056"},"relatedVulnerabilities":[{"id":"CVE-2019-16056","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16056","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-16056","date":"2026-10-08","epss":0.0512,"percentile":0.9217}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00062.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00063.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00012.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00021.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","https://access.redhat.com/errata/RHSA-2019:3725","https://access.redhat.com/errata/RHSA-2019:3948","https://bugs.python.org/issue34155","https://github.com/python/cpython/commit/8cb65d1381b027f0b09ee36bfed7f35bb4dec9a9","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/09/msg00018.html","https://lists.debian.org/debian-lts-announce/2019/09/msg00019.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEARDOTXCYPYELKBD2KWZ27GSPXDI3GQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/COATURTCY7G67AYI6UDV5B2JZTBCKIDX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K4KZEFP6E4YPYB52AF4WXCUDSGQOTF37/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K7HNVIFMETMFWWWUNTB72KYJYXCZOS5V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NF3DRDGMVIRYNZMSLJIHNW47HOUQYXVG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OYGESQSGIHDCIGOBVF7VXCMIE6YDWRYB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QASRD4E2G65GGEHYKVHYCXB2XWAGTNL4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QP46PQSUKYPGWTADQ67NOV3BUN6JM34Z/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SDQQ56P7ZZR64XV5DUVWNSNXKKEXUG2J/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBTGPBUABGXZ7WH7677OEM3NSP6ZEA76/","https://security.netapp.com/advisory/ntap-20190926-0005/","https://usn.ubuntu.com/4151-1/","https://usn.ubuntu.com/4151-2/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16056","description":"An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.12.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjjh-jjxp-wpff","versionConstraint":">=2.4.0-rc1,<2.12.7.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-jjjh-jjxp-wpff","fix":{"state":"fixed","versions":["2.12.7.1"],"available":[{"date":"2022-11-16","kind":"first-observed","version":"2.12.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42003","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42003","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42003","date":"2026-10-08","epss":0.03409,"percentile":0.88545}],"risk":2.55675,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-42003","https://github.com/FasterXML/jackson-databind/issues/3590","https://github.com/FasterXML/jackson-databind/commit/d78d00ee7b5245b93103fef3187f70543d67ca33","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=51020","https://github.com/FasterXML/jackson-databind/blob/2.13/release-notes/VERSION-2.x","https://security.gentoo.org/glsa/202210-21","https://github.com/FasterXML/jackson-databind/issues/3627","https://github.com/FasterXML/jackson-databind/commit/cd090979b7ea78c75e4de8a4aed04f7e9fa8deea","https://www.debian.org/security/2022/dsa-5283","https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","https://github.com/FasterXML/jackson-databind/commit/7ba9ac5b87a9d6ac0d2815158ecbeb315ad4dcdc","https://github.com/FasterXML/jackson-databind/commit/0e37a39502439ecbaa1a5b5188387c01bf7f7fa1","https://github.com/FasterXML/jackson-databind/commit/d499f2e7bbc5ebd63af11e1f5cf1989fa323aa45","https://github.com/FasterXML/jackson-databind/commits/jackson-databind-2.4.0-rc1?after=75b97b8519f0d50c62523ad85170d80a197a2c86+174&branch=jackson-databind-2.4.0-rc1&qualified_name=refs%2Ftags%2Fjackson-databind-2.4.0-rc1","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.13.4.1...jackson-databind-2.13.4.2","https://github.com/FasterXML/jackson-databind/commit/2c4a601c626f7790cad9d3c322d244e182838288","https://security.netapp.com/advisory/ntap-20221124-0004"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjjh-jjxp-wpff","description":"Uncontrolled Resource Consumption in Jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2022-42003","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42003","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42003","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42003","date":"2026-10-08","epss":0.03409,"percentile":0.88545}],"urls":["https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=51020","https://github.com/FasterXML/jackson-databind/commit/d78d00ee7b5245b93103fef3187f70543d67ca33","https://github.com/FasterXML/jackson-databind/issues/3590","https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","https://security.gentoo.org/glsa/202210-21","https://security.netapp.com/advisory/ntap-20221124-0004/","https://www.debian.org/security/2022/dsa-5283"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42003","description":"In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled."}]},{"artifact":{"id":"b4f646c66dd594d4","cpes":["cpe:2.3:a:gzip:gzip:1.6-5ubuntu1:*:*:*:*:*:*:*"],"name":"gzip","purl":"pkg:deb/ubuntu/gzip@1.6-5ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.6-5ubuntu1","language":"","licenses":["sha256:f9ac4a5d7a670e3891881a2cdba5fa2cd625c4d58eae4a7aa372ac00a06803bd"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gzip/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/gzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/gzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.list","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/gzip.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.6-5ubuntu1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-1271","versionConstraint":"< 1.6-5ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"gzip","version":"1.6-5ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-1271","fix":{"state":"fixed","versions":["1.6-5ubuntu1.2"],"available":[{"date":"2022-04-13","kind":"advisory","version":"1.6-5ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-1271","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1271","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1271","date":"2026-10-08","epss":0.0507,"percentile":0.92107}],"risk":2.535,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1271"},"relatedVulnerabilities":[{"id":"CVE-2022-1271","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1271","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1271","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1271","date":"2026-10-08","epss":0.0507,"percentile":0.92107}],"urls":["https://access.redhat.com/security/cve/CVE-2022-1271","https://bugzilla.redhat.com/show_bug.cgi?id=2073310","https://git.tukaani.org/?p=xz.git%3Ba=commit%3Bh=69d1b3fc29677af8ade8dc15dba83f0589cb63d6","https://lists.gnu.org/r/bug-gzip/2022-04/msg00011.html","https://security-tracker.debian.org/tracker/CVE-2022-1271","https://security.gentoo.org/glsa/202209-01","https://security.netapp.com/advisory/ntap-20220930-0006/","https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch","https://www.openwall.com/lists/oss-security/2022/04/07/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1271","description":"An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system."}]},{"artifact":{"id":"bde30df0cdd91b38","cpes":["cpe:2.3:a:liblzma5:liblzma5:5.2.2-1.3:*:*:*:*:*:*:*"],"name":"liblzma5","purl":"pkg:deb/ubuntu/liblzma5@5.2.2-1.3?arch=amd64&distro=ubuntu-18.04&upstream=xz-utils","type":"deb","version":"5.2.2-1.3","language":"","licenses":["Autoconf","GPL-2","GPL-2+","GPL-3","LGPL-2","LGPL-2.1","LGPL-2.1+","PD","PD-debian","config-h","noderivs","permissive-fsf","permissive-nowarranty","probably-PD"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblzma5/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/liblzma5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblzma5:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/liblzma5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"xz-utils"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.2.2-1.3ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-1271","versionConstraint":"< 5.2.2-1.3ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"xz-utils","version":"5.2.2-1.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-1271","fix":{"state":"fixed","versions":["5.2.2-1.3ubuntu0.1"],"available":[{"date":"2022-04-13","kind":"advisory","version":"5.2.2-1.3ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-1271","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1271","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1271","date":"2026-10-08","epss":0.0507,"percentile":0.92107}],"risk":2.535,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1271"},"relatedVulnerabilities":[{"id":"CVE-2022-1271","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1271","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1271","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1271","date":"2026-10-08","epss":0.0507,"percentile":0.92107}],"urls":["https://access.redhat.com/security/cve/CVE-2022-1271","https://bugzilla.redhat.com/show_bug.cgi?id=2073310","https://git.tukaani.org/?p=xz.git%3Ba=commit%3Bh=69d1b3fc29677af8ade8dc15dba83f0589cb63d6","https://lists.gnu.org/r/bug-gzip/2022-04/msg00011.html","https://security-tracker.debian.org/tracker/CVE-2022-1271","https://security.gentoo.org/glsa/202209-01","https://security.netapp.com/advisory/ntap-20220930-0006/","https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch","https://www.openwall.com/lists/oss-security/2022/04/07/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1271","description":"An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-48565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-48565","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"risk":2.5325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-48565"},"relatedVulnerabilities":[{"id":"CVE-2022-48565","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"urls":["https://bugs.python.org/issue42051","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFHYAGWBFBNUGWU6XWKBHTCV5NH77MB7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAYWJD576JUKLHCWKDLMJSUGTRDKPF3M/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZRZRJHWLZ7MOJNPQBWGJVXMVYDC5BRA/","https://security.netapp.com/advisory/ntap-20231006-0007/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-48565","description":"An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-48565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-48565","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"risk":2.5325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-48565"},"relatedVulnerabilities":[{"id":"CVE-2022-48565","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"urls":["https://bugs.python.org/issue42051","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFHYAGWBFBNUGWU6XWKBHTCV5NH77MB7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAYWJD576JUKLHCWKDLMJSUGTRDKPF3M/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZRZRJHWLZ7MOJNPQBWGJVXMVYDC5BRA/","https://security.netapp.com/advisory/ntap-20231006-0007/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-48565","description":"An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities."}]},{"artifact":{"id":"fde2411575cfc3ee","cpes":["cpe:2.3:a:python:python:2.7.15\\~rc1-1:*:*:*:*:*:*:*"],"name":"python","purl":"pkg:deb/ubuntu/python@2.7.15~rc1-1?arch=amd64&distro=ubuntu-18.04&upstream=python-defaults","type":"deb","version":"2.7.15~rc1-1","language":"","licenses":["sha256:7238b66ed531f0c810a8099d5fc296d8eaa43c2ea6966458e4222ec548f2b44a"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python.list"},{"path":"/var/lib/dpkg/info/python.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python.postinst"},{"path":"/var/lib/dpkg/info/python.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python.postrm"},{"path":"/var/lib/dpkg/info/python.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python.preinst"},{"path":"/var/lib/dpkg/info/python.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python.prerm"}],"upstreams":[{"name":"python-defaults"}]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-48565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python","version":"2.7.15~rc1-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-48565","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"risk":2.5325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-48565"},"relatedVulnerabilities":[{"id":"CVE-2022-48565","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"urls":["https://bugs.python.org/issue42051","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFHYAGWBFBNUGWU6XWKBHTCV5NH77MB7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAYWJD576JUKLHCWKDLMJSUGTRDKPF3M/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZRZRJHWLZ7MOJNPQBWGJVXMVYDC5BRA/","https://security.netapp.com/advisory/ntap-20231006-0007/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-48565","description":"An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-48565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-48565","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"risk":2.5325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-48565"},"relatedVulnerabilities":[{"id":"CVE-2022-48565","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"urls":["https://bugs.python.org/issue42051","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFHYAGWBFBNUGWU6XWKBHTCV5NH77MB7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAYWJD576JUKLHCWKDLMJSUGTRDKPF3M/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZRZRJHWLZ7MOJNPQBWGJVXMVYDC5BRA/","https://security.netapp.com/advisory/ntap-20231006-0007/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-48565","description":"An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-48565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-48565","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"risk":2.5325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-48565"},"relatedVulnerabilities":[{"id":"CVE-2022-48565","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"urls":["https://bugs.python.org/issue42051","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFHYAGWBFBNUGWU6XWKBHTCV5NH77MB7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAYWJD576JUKLHCWKDLMJSUGTRDKPF3M/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZRZRJHWLZ7MOJNPQBWGJVXMVYDC5BRA/","https://security.netapp.com/advisory/ntap-20231006-0007/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-48565","description":"An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities."}]},{"artifact":{"id":"0c17bed56057f9e7","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.1?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-13565","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-13565","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.3"],"available":[{"date":"2019-07-30","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.3"}]},"cvss":[],"epss":[{"cve":"CVE-2019-13565","date":"2026-10-08","epss":0.05015,"percentile":0.92033}],"risk":2.5075,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-13565"},"relatedVulnerabilities":[{"id":"CVE-2019-13565","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-13565","date":"2026-10-08","epss":0.05015,"percentile":0.92033}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html","http://seclists.org/fulldisclosure/2019/Dec/26","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/08/msg00024.html","https://seclists.org/bugtraq/2019/Dec/23","https://support.apple.com/kb/HT210788","https://support.f5.com/csp/article/K98008862?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4078-1/","https://usn.ubuntu.com/4078-2/","https://www.openldap.org/its/index.cgi/?findid=9052","https://www.openldap.org/lists/openldap-announce/201907/msg00001.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-13565","description":"An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs. After the first SASL bind is completed, the sasl_ssf value is retained for all new non-SASL connections. Depending on the ACL configuration, this can affect different types of operations (searches, modifications, etc.). In other words, a successful authorization step completed by one user affects the authorization requirement for a different user."}]},{"artifact":{"id":"d1ea226d64532803","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.1?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-13565","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-13565","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.3"],"available":[{"date":"2019-07-30","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.3"}]},"cvss":[],"epss":[{"cve":"CVE-2019-13565","date":"2026-10-08","epss":0.05015,"percentile":0.92033}],"risk":2.5075,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-13565"},"relatedVulnerabilities":[{"id":"CVE-2019-13565","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-13565","date":"2026-10-08","epss":0.05015,"percentile":0.92033}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html","http://seclists.org/fulldisclosure/2019/Dec/26","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/08/msg00024.html","https://seclists.org/bugtraq/2019/Dec/23","https://support.apple.com/kb/HT210788","https://support.f5.com/csp/article/K98008862?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4078-1/","https://usn.ubuntu.com/4078-2/","https://www.openldap.org/its/index.cgi/?findid=9052","https://www.openldap.org/lists/openldap-announce/201907/msg00001.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-13565","description":"An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs. After the first SASL bind is completed, the sasl_ssf value is retained for all new non-SASL connections. Depending on the ACL configuration, this can affect different types of operations (searches, modifications, etc.). In other words, a successful authorization step completed by one user affects the authorization requirement for a different user."}]},{"artifact":{"id":"5db993d4de01e7b1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.6","type":"java-archive","version":"2.9.6","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"cfa4f316351a91bfd95cb0644c6a2c95f52db1fc","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/jackson-databind-2.9.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-95cm-88f5-f2c7","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-95cm-88f5-f2c7","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10672","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10672","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10672","date":"2026-10-08","epss":0.03059,"percentile":0.87211}],"risk":2.493085,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-10672","https://github.com/FasterXML/jackson-databind/issues/2659","https://lists.debian.org/debian-lts-announce/2020/03/msg00027.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://github.com/FasterXML/jackson-databind/commit/592872f4235c7f2a3280725278da55544032f72d","https://security.netapp.com/advisory/ntap-20200403-0002","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-95cm-88f5-f2c7","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-10672","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10672","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10672","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10672","date":"2026-10-08","epss":0.03059,"percentile":0.87211}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2659","https://lists.debian.org/debian-lts-announce/2020/03/msg00027.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10672","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.7+10-2ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-2830","versionConstraint":"< 11.0.7+10-2ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-2830","fix":{"state":"fixed","versions":["11.0.7+10-2ubuntu2~18.04"],"available":[{"date":"2020-04-22","kind":"advisory","version":"11.0.7+10-2ubuntu2~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2020-2830","date":"2026-10-08","epss":0.04948,"percentile":0.91941}],"risk":2.474,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-2830"},"relatedVulnerabilities":[{"id":"CVE-2020-2830","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-2830","date":"2026-10-08","epss":0.04948,"percentile":0.91941}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00000.html","http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00023.html","http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00048.html","https://kc.mcafee.com/corporate/index?page=content&id=SB10318","https://lists.debian.org/debian-lts-announce/2020/04/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CKAV6KFFAEANXAN73AFTGU7Z6YNRWCXQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7VHC4EW36KZEIDQ56RPCWBZCQELFFKN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NYHHHZRHXCBGRHGE5UP7UEB4IZ2QX536/","https://security.gentoo.org/glsa/202006-22","https://security.netapp.com/advisory/ntap-20200416-0004/","https://usn.ubuntu.com/4337-1/","https://www.debian.org/security/2020/dsa-4662","https://www.oracle.com/security-alerts/cpuapr2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-2830","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.14"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-22925","versionConstraint":"< 7.58.0-2ubuntu3.14 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22925","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.14"],"available":[{"date":"2021-07-22","kind":"advisory","version":"7.58.0-2ubuntu3.14"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22925","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22925","cwe":"CWE-908","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22925","date":"2026-10-08","epss":0.04929,"percentile":0.91913}],"risk":2.4645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22925"},"relatedVulnerabilities":[{"id":"CVE-2021-22925","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22925","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22925","cwe":"CWE-908","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22925","date":"2026-10-08","epss":0.04929,"percentile":0.91913}],"urls":["http://seclists.org/fulldisclosure/2021/Sep/39","http://seclists.org/fulldisclosure/2021/Sep/40","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://hackerone.com/reports/1223882","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20210902-0003/","https://support.apple.com/kb/HT212804","https://support.apple.com/kb/HT212805","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22925","description":"curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.14"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-22925","versionConstraint":"< 7.58.0-2ubuntu3.14 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22925","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.14"],"available":[{"date":"2021-07-22","kind":"advisory","version":"7.58.0-2ubuntu3.14"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22925","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22925","cwe":"CWE-908","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22925","date":"2026-10-08","epss":0.04929,"percentile":0.91913}],"risk":2.4645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22925"},"relatedVulnerabilities":[{"id":"CVE-2021-22925","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22925","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22925","cwe":"CWE-908","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22925","date":"2026-10-08","epss":0.04929,"percentile":0.91913}],"urls":["http://seclists.org/fulldisclosure/2021/Sep/39","http://seclists.org/fulldisclosure/2021/Sep/40","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://hackerone.com/reports/1223882","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20210902-0003/","https://support.apple.com/kb/HT212804","https://support.apple.com/kb/HT212805","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22925","description":"curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.20"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-2097","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.20 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-2097","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.20"],"available":[{"date":"2022-07-05","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.20"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-2097","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-2097","date":"2026-10-08","epss":0.04899,"percentile":0.91868}],"risk":2.4495,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-2097"},"relatedVulnerabilities":[{"id":"CVE-2022-2097","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-2097","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-2097","date":"2026-10-08","epss":0.04899,"percentile":0.91868}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=919925673d6c9cfed3c1085497f5dfbbed5fc431","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a98f339ddd7e8f487d6e0088d4a9a42324885a93","https://lists.debian.org/debian-lts-announce/2023/02/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20220715-0011/","https://security.netapp.com/advisory/ntap-20230420-0008/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2023/dsa-5343","https://www.openssl.org/news/secadv/20220705.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-2097","description":"AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of \"in place\" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p)."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.20"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-2097","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.20 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-2097","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.20"],"available":[{"date":"2022-07-05","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.20"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-2097","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-2097","date":"2026-10-08","epss":0.04899,"percentile":0.91868}],"risk":2.4495,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-2097"},"relatedVulnerabilities":[{"id":"CVE-2022-2097","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-2097","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-2097","date":"2026-10-08","epss":0.04899,"percentile":0.91868}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=919925673d6c9cfed3c1085497f5dfbbed5fc431","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a98f339ddd7e8f487d6e0088d4a9a42324885a93","https://lists.debian.org/debian-lts-announce/2023/02/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20220715-0011/","https://security.netapp.com/advisory/ntap-20230420-0008/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2023/dsa-5343","https://www.openssl.org/news/secadv/20220705.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-2097","description":"AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of \"in place\" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.6+10-1ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-2604","versionConstraint":"< 11.0.6+10-1ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-2604","fix":{"state":"fixed","versions":["11.0.6+10-1ubuntu1~18.04.1"],"available":[{"date":"2020-01-28","kind":"advisory","version":"11.0.6+10-1ubuntu1~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-2604","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-2604","date":"2026-10-08","epss":0.04881,"percentile":0.91839}],"risk":2.4405,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-2604"},"relatedVulnerabilities":[{"id":"CVE-2020-2604","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-2604","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-2604","date":"2026-10-08","epss":0.04881,"percentile":0.91839}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00050.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00060.html","https://access.redhat.com/errata/RHSA-2020:0122","https://access.redhat.com/errata/RHSA-2020:0128","https://access.redhat.com/errata/RHSA-2020:0196","https://access.redhat.com/errata/RHSA-2020:0202","https://access.redhat.com/errata/RHSA-2020:0231","https://access.redhat.com/errata/RHSA-2020:0232","https://access.redhat.com/errata/RHSA-2020:0465","https://access.redhat.com/errata/RHSA-2020:0467","https://access.redhat.com/errata/RHSA-2020:0468","https://access.redhat.com/errata/RHSA-2020:0469","https://access.redhat.com/errata/RHSA-2020:0470","https://access.redhat.com/errata/RHSA-2020:0541","https://access.redhat.com/errata/RHSA-2020:0632","https://kc.mcafee.com/corporate/index?page=content&id=SB10315","https://lists.debian.org/debian-lts-announce/2020/02/msg00034.html","https://seclists.org/bugtraq/2020/Feb/22","https://security.gentoo.org/glsa/202101-19","https://security.netapp.com/advisory/ntap-20200122-0003/","https://usn.ubuntu.com/4257-1/","https://www.debian.org/security/2020/dsa-4621","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-2604","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS v3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-30761","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2025-30761","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-30761","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-30761","date":"2026-10-08","epss":0.04873,"percentile":0.91827}],"risk":2.4365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-30761"},"relatedVulnerabilities":[{"id":"CVE-2025-30761","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30761","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-30761","date":"2026-10-08","epss":0.04873,"percentile":0.91827}],"urls":["https://www.oracle.com/security-alerts/cpujul2025.html","http://www.openwall.com/lists/oss-security/2025/07/16/1","http://www.openwall.com/lists/oss-security/2025/07/21/3","http://www.openwall.com/lists/oss-security/2025/07/24/1","https://lists.debian.org/debian-lts-announce/2025/07/msg00011.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30761","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting).  Supported versions that are affected are Oracle Java SE: 8u451, 8u451-perf and  11.0.27; Oracle GraalVM Enterprise Edition: 21.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)."}]},{"artifact":{"id":"0b1c74783f88c915","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.22.0-1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9936","versionConstraint":"< 3.22.0-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9936","fix":{"state":"fixed","versions":["3.22.0-1ubuntu0.1"],"available":[{"date":"2019-06-19","kind":"advisory","version":"3.22.0-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9936","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9936","date":"2026-10-08","epss":0.04843,"percentile":0.91782}],"risk":2.4215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9936"},"relatedVulnerabilities":[{"id":"CVE-2019-9936","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9936","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9936","date":"2026-10-08","epss":0.04843,"percentile":0.91782}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00026.html","http://www.securityfocus.com/bid/107562","https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXD2GYJVTDGEQPUNMMMC5TB7MQXOBBMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N66U5PY5UJU4XBFZJH7QNKIDNAVIB4OP/","https://security.gentoo.org/glsa/201908-09","https://security.netapp.com/advisory/ntap-20190416-0005/","https://sqlite.org/src/info/b3fa58dd7403dbd4","https://usn.ubuntu.com/4019-1/","https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114382.html","https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114394.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9936","description":"In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c."}]},{"artifact":{"id":"88bdd6da7cccc159","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-22822","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-22822","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-22822","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22822","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22822","date":"2026-10-08","epss":0.04829,"percentile":0.9176}],"risk":2.4145,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-22822"},"relatedVulnerabilities":[{"id":"CVE-2022-22822","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22822","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22822","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22822","date":"2026-10-08","epss":0.04829,"percentile":0.9176}],"urls":["http://www.openwall.com/lists/oss-security/2022/01/17/3","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/539","https://security.gentoo.org/glsa/202209-24","https://www.debian.org/security/2022/dsa-5073","https://www.tenable.com/security/tns-2022-05"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22822","description":"addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow."}]},{"artifact":{"id":"88bdd6da7cccc159","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-25315","versionConstraint":"< 2.2.5-3ubuntu0.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-25315","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.7"],"available":[{"date":"2022-03-10","kind":"advisory","version":"2.2.5-3ubuntu0.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-25315","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25315","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25315","date":"2026-10-08","epss":0.04821,"percentile":0.91746}],"risk":2.4105000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-25315"},"relatedVulnerabilities":[{"id":"CVE-2022-25315","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25315","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25315","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25315","date":"2026-10-08","epss":0.04821,"percentile":0.91746}],"urls":["http://www.openwall.com/lists/oss-security/2022/02/19/1","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/559","https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/","https://security.gentoo.org/glsa/202209-24","https://security.netapp.com/advisory/ntap-20220303-0008/","https://www.debian.org/security/2022/dsa-5085","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25315","description":"In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames."}]},{"artifact":{"id":"0b1c74783f88c915","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-19603","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-19603","fix":{"state":"wont-fix","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-19603","date":"2026-10-08","epss":0.0803,"percentile":0.94645}],"risk":2.409,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-19603"},"relatedVulnerabilities":[{"id":"CVE-2019-19603","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-19603","date":"2026-10-08","epss":0.0803,"percentile":0.94645}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://github.com/sqlite/sqlite/commit/527cbd4a104cb93bf3994b3dd3619a6299a78b13","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E","https://security.netapp.com/advisory/ntap-20191223-0001/","https://usn.ubuntu.com/4394-1/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.sqlite.org/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19603","description":"SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash."}]},{"artifact":{"id":"0b1c74783f88c915","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.22.0-1ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-8740","versionConstraint":"< 3.22.0-1ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-8740","fix":{"state":"fixed","versions":["3.22.0-1ubuntu0.4"],"available":[{"date":"2020-06-10","kind":"advisory","version":"3.22.0-1ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-8740","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-8740","date":"2026-10-08","epss":0.07966,"percentile":0.94609}],"risk":2.3897999999999997,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-8740"},"relatedVulnerabilities":[{"id":"CVE-2018-8740","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-8740","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-8740","date":"2026-10-08","epss":0.07966,"percentile":0.94609}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00050.html","http://www.securityfocus.com/bid/103466","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=6964","https://bugs.launchpad.net/ubuntu/+source/sqlite3/+bug/1756349","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/01/msg00009.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PU4NZ6DDU4BEM3ACM3FM6GLEPX56ZQXK/","https://usn.ubuntu.com/4205-1/","https://usn.ubuntu.com/4394-1/","https://www.sqlite.org/cgi/src/timeline?r=corrupt-schema","https://www.sqlite.org/cgi/src/vdiff?from=1774f1c3baf0bc3d&to=d75e67654aa9620b"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-8740","description":"In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, related to build.c and prepare.c."}]},{"artifact":{"id":"88bdd6da7cccc159","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-25314","versionConstraint":"< 2.2.5-3ubuntu0.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-25314","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.7"],"available":[{"date":"2022-03-10","kind":"advisory","version":"2.2.5-3ubuntu0.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-25314","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25314","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25314","date":"2026-10-08","epss":0.04693,"percentile":0.91557}],"risk":2.3465,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-25314"},"relatedVulnerabilities":[{"id":"CVE-2022-25314","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25314","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25314","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25314","date":"2026-10-08","epss":0.04693,"percentile":0.91557}],"urls":["http://www.openwall.com/lists/oss-security/2022/02/19/1","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/560","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/","https://security.gentoo.org/glsa/202209-24","https://security.netapp.com/advisory/ntap-20220303-0008/","https://www.debian.org/security/2022/dsa-5085","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25314","description":"In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.21"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-32221","versionConstraint":"< 7.58.0-2ubuntu3.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-32221","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.21"],"available":[{"date":"2022-10-26","kind":"advisory","version":"7.58.0-2ubuntu3.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-32221","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32221","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32221","date":"2026-10-08","epss":0.04676,"percentile":0.91537}],"risk":2.338,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-32221"},"relatedVulnerabilities":[{"id":"CVE-2022-32221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-32221","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32221","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32221","date":"2026-10-08","epss":0.04676,"percentile":0.91537}],"urls":["http://seclists.org/fulldisclosure/2023/Jan/19","http://seclists.org/fulldisclosure/2023/Jan/20","http://www.openwall.com/lists/oss-security/2023/05/17/4","https://hackerone.com/reports/1704017","https://lists.debian.org/debian-lts-announce/2023/01/msg00028.html","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20230110-0006/","https://security.netapp.com/advisory/ntap-20230208-0002/","https://support.apple.com/kb/HT213604","https://support.apple.com/kb/HT213605","https://www.debian.org/security/2023/dsa-5330"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-32221","description":"When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.21"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-32221","versionConstraint":"< 7.58.0-2ubuntu3.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-32221","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.21"],"available":[{"date":"2022-10-26","kind":"advisory","version":"7.58.0-2ubuntu3.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-32221","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32221","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32221","date":"2026-10-08","epss":0.04676,"percentile":0.91537}],"risk":2.338,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-32221"},"relatedVulnerabilities":[{"id":"CVE-2022-32221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-32221","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32221","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32221","date":"2026-10-08","epss":0.04676,"percentile":0.91537}],"urls":["http://seclists.org/fulldisclosure/2023/Jan/19","http://seclists.org/fulldisclosure/2023/Jan/20","http://www.openwall.com/lists/oss-security/2023/05/17/4","https://hackerone.com/reports/1704017","https://lists.debian.org/debian-lts-announce/2023/01/msg00028.html","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20230110-0006/","https://security.netapp.com/advisory/ntap-20230208-0002/","https://support.apple.com/kb/HT213604","https://support.apple.com/kb/HT213605","https://www.debian.org/security/2023/dsa-5330"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-32221","description":"When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-8286","versionConstraint":"< 7.58.0-2ubuntu3.12 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-8286","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.12"],"available":[{"date":"2020-12-09","kind":"advisory","version":"7.58.0-2ubuntu3.12"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-8286","cwe":"CWE-295","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2020-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8286","date":"2026-10-08","epss":0.04631,"percentile":0.9147}],"risk":2.3154999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-8286"},"relatedVulnerabilities":[{"id":"CVE-2020-8286","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8286","cwe":"CWE-295","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2020-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8286","date":"2026-10-08","epss":0.04631,"percentile":0.9147}],"urls":["http://seclists.org/fulldisclosure/2021/Apr/50","http://seclists.org/fulldisclosure/2021/Apr/51","http://seclists.org/fulldisclosure/2021/Apr/54","https://cert-portal.siemens.com/productcert/pdf/ssa-200951.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://curl.se/docs/CVE-2020-8286.html","https://hackerone.com/reports/1048457","https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/","https://security.gentoo.org/glsa/202012-14","https://security.netapp.com/advisory/ntap-20210122-0007/","https://support.apple.com/kb/HT212325","https://support.apple.com/kb/HT212326","https://support.apple.com/kb/HT212327","https://www.debian.org/security/2021/dsa-4881","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8286","description":"curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.12"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-8286","versionConstraint":"< 7.58.0-2ubuntu3.12 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-8286","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.12"],"available":[{"date":"2020-12-09","kind":"advisory","version":"7.58.0-2ubuntu3.12"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-8286","cwe":"CWE-295","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2020-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8286","date":"2026-10-08","epss":0.04631,"percentile":0.9147}],"risk":2.3154999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-8286"},"relatedVulnerabilities":[{"id":"CVE-2020-8286","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8286","cwe":"CWE-295","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2020-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8286","date":"2026-10-08","epss":0.04631,"percentile":0.9147}],"urls":["http://seclists.org/fulldisclosure/2021/Apr/50","http://seclists.org/fulldisclosure/2021/Apr/51","http://seclists.org/fulldisclosure/2021/Apr/54","https://cert-portal.siemens.com/productcert/pdf/ssa-200951.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://curl.se/docs/CVE-2020-8286.html","https://hackerone.com/reports/1048457","https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/","https://security.gentoo.org/glsa/202012-14","https://security.netapp.com/advisory/ntap-20210122-0007/","https://support.apple.com/kb/HT212325","https://support.apple.com/kb/HT212326","https://support.apple.com/kb/HT212327","https://www.debian.org/security/2021/dsa-4881","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8286","description":"curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response."}]},{"artifact":{"id":"88bdd6da7cccc159","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23852","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-23852","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-23852","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23852","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23852","date":"2026-10-08","epss":0.04563,"percentile":0.9136}],"risk":2.2815,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23852"},"relatedVulnerabilities":[{"id":"CVE-2022-23852","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23852","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23852","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23852","date":"2026-10-08","epss":0.04563,"percentile":0.9136}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/550","https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html","https://security.gentoo.org/glsa/202209-24","https://security.netapp.com/advisory/ntap-20220217-0001/","https://www.debian.org/security/2022/dsa-5073","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.tenable.com/security/tns-2022-05"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23852","description":"Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-22946","versionConstraint":"< 7.58.0-2ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22946","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.15"],"available":[{"date":"2021-09-15","kind":"advisory","version":"7.58.0-2ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22946","cwe":"CWE-325","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22946","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-22946","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-22946","date":"2026-10-08","epss":0.04539,"percentile":0.91321}],"risk":2.2695,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22946"},"relatedVulnerabilities":[{"id":"CVE-2021-22946","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22946","cwe":"CWE-325","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22946","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-22946","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-22946","date":"2026-10-08","epss":0.04539,"percentile":0.91321}],"urls":["http://seclists.org/fulldisclosure/2022/Mar/29","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://hackerone.com/reports/1334111","https://lists.debian.org/debian-lts-announce/2021/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20211029-0003/","https://security.netapp.com/advisory/ntap-20220121-0008/","https://support.apple.com/kb/HT213183","https://www.debian.org/security/2022/dsa-5197","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22946","description":"A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-22946","versionConstraint":"< 7.58.0-2ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22946","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.15"],"available":[{"date":"2021-09-15","kind":"advisory","version":"7.58.0-2ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22946","cwe":"CWE-325","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22946","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-22946","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-22946","date":"2026-10-08","epss":0.04539,"percentile":0.91321}],"risk":2.2695,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22946"},"relatedVulnerabilities":[{"id":"CVE-2021-22946","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22946","cwe":"CWE-325","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22946","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-22946","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-22946","date":"2026-10-08","epss":0.04539,"percentile":0.91321}],"urls":["http://seclists.org/fulldisclosure/2022/Mar/29","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://hackerone.com/reports/1334111","https://lists.debian.org/debian-lts-announce/2021/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20211029-0003/","https://security.netapp.com/advisory/ntap-20220121-0008/","https://support.apple.com/kb/HT213183","https://www.debian.org/security/2022/dsa-5197","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22946","description":"A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.21"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-0215","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-0215","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.21"],"available":[{"date":"2023-02-07","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-0215","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0215","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0215","date":"2026-10-08","epss":0.04494,"percentile":0.91248}],"risk":2.247,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-0215"},"relatedVulnerabilities":[{"id":"CVE-2023-0215","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-0215","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0215","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0215","date":"2026-10-08","epss":0.04494,"percentile":0.91248}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8818064ce3c3c0f1b740a5aaba2a987e75bfbafd","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9816136fe31d92ace4037d5da5257f763aeeb4eb","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=c3829dd8825c654652201e16f8a0a0c46ee3f344","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230427-0007/","https://security.netapp.com/advisory/ntap-20230427-0009/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.openssl.org/news/secadv/20230207.txt","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-0215","description":"The public API function BIO_new_NDEF is a helper function used for streaming\nASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the\nSMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by\nend user applications.\n\nThe function receives a BIO from the caller, prepends a new BIO_f_asn1 filter\nBIO onto the front of it to form a BIO chain, and then returns the new head of\nthe BIO chain to the caller. Under certain conditions, for example if a CMS\nrecipient public key is invalid, the new filter BIO is freed and the function\nreturns a NULL result indicating a failure. However, in this case, the BIO chain\nis not properly cleaned up and the BIO passed by the caller still retains\ninternal pointers to the previously freed filter BIO. If the caller then goes on\nto call BIO_pop() on the BIO then a use-after-free will occur. This will most\nlikely result in a crash.\n\n\n\nThis scenario occurs directly in the internal function B64_write_ASN1() which\nmay cause BIO_new_NDEF() to be called and will subsequently call BIO_pop() on\nthe BIO. This internal function is in turn called by the public API functions\nPEM_write_bio_ASN1_stream, PEM_write_bio_CMS_stream, PEM_write_bio_PKCS7_stream,\nSMIME_write_ASN1, SMIME_write_CMS and SMIME_write_PKCS7.\n\nOther public API functions that may be impacted by this include\ni2d_ASN1_bio_stream, BIO_new_CMS, BIO_new_PKCS7, i2d_CMS_bio_stream and\ni2d_PKCS7_bio_stream.\n\nThe OpenSSL cms and smime command line applications are similarly affected."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.21"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-0215","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-0215","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.21"],"available":[{"date":"2023-02-07","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-0215","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0215","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0215","date":"2026-10-08","epss":0.04494,"percentile":0.91248}],"risk":2.247,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-0215"},"relatedVulnerabilities":[{"id":"CVE-2023-0215","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-0215","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0215","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0215","date":"2026-10-08","epss":0.04494,"percentile":0.91248}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8818064ce3c3c0f1b740a5aaba2a987e75bfbafd","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9816136fe31d92ace4037d5da5257f763aeeb4eb","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=c3829dd8825c654652201e16f8a0a0c46ee3f344","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230427-0007/","https://security.netapp.com/advisory/ntap-20230427-0009/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.openssl.org/news/secadv/20230207.txt","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-0215","description":"The public API function BIO_new_NDEF is a helper function used for streaming\nASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the\nSMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by\nend user applications.\n\nThe function receives a BIO from the caller, prepends a new BIO_f_asn1 filter\nBIO onto the front of it to form a BIO chain, and then returns the new head of\nthe BIO chain to the caller. Under certain conditions, for example if a CMS\nrecipient public key is invalid, the new filter BIO is freed and the function\nreturns a NULL result indicating a failure. However, in this case, the BIO chain\nis not properly cleaned up and the BIO passed by the caller still retains\ninternal pointers to the previously freed filter BIO. If the caller then goes on\nto call BIO_pop() on the BIO then a use-after-free will occur. This will most\nlikely result in a crash.\n\n\n\nThis scenario occurs directly in the internal function B64_write_ASN1() which\nmay cause BIO_new_NDEF() to be called and will subsequently call BIO_pop() on\nthe BIO. This internal function is in turn called by the public API functions\nPEM_write_bio_ASN1_stream, PEM_write_bio_CMS_stream, PEM_write_bio_PKCS7_stream,\nSMIME_write_ASN1, SMIME_write_CMS and SMIME_write_PKCS7.\n\nOther public API functions that may be impacted by this include\ni2d_ASN1_bio_stream, BIO_new_CMS, BIO_new_PKCS7, i2d_CMS_bio_stream and\ni2d_PKCS7_bio_stream.\n\nThe OpenSSL cms and smime command line applications are similarly affected."}]},{"artifact":{"id":"0c17bed56057f9e7","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.1?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-12243","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-12243","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.5"],"available":[{"date":"2020-05-06","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-12243","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-12243","date":"2026-10-08","epss":0.04423,"percentile":0.91112}],"risk":2.2115,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-12243"},"relatedVulnerabilities":[{"id":"CVE-2020-12243","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-12243","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-12243","date":"2026-10-08","epss":0.04423,"percentile":0.91112}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00016.html","https://bugs.openldap.org/show_bug.cgi?id=9202","https://git.openldap.org/openldap/openldap/-/blob/OPENLDAP_REL_ENG_2_4/CHANGES","https://git.openldap.org/openldap/openldap/-/commit/98464c11df8247d6a11b52e294ba5dd4f0380440","https://lists.debian.org/debian-lts-announce/2020/05/msg00001.html","https://security.netapp.com/advisory/ntap-20200511-0003/","https://support.apple.com/kb/HT211289","https://usn.ubuntu.com/4352-1/","https://usn.ubuntu.com/4352-2/","https://www.debian.org/security/2020/dsa-4666","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-12243","description":"In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash)."}]},{"artifact":{"id":"d1ea226d64532803","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.1?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-12243","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-12243","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.5"],"available":[{"date":"2020-05-06","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-12243","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-12243","date":"2026-10-08","epss":0.04423,"percentile":0.91112}],"risk":2.2115,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-12243"},"relatedVulnerabilities":[{"id":"CVE-2020-12243","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-12243","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-12243","date":"2026-10-08","epss":0.04423,"percentile":0.91112}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00016.html","https://bugs.openldap.org/show_bug.cgi?id=9202","https://git.openldap.org/openldap/openldap/-/blob/OPENLDAP_REL_ENG_2_4/CHANGES","https://git.openldap.org/openldap/openldap/-/commit/98464c11df8247d6a11b52e294ba5dd4f0380440","https://lists.debian.org/debian-lts-announce/2020/05/msg00001.html","https://security.netapp.com/advisory/ntap-20200511-0003/","https://support.apple.com/kb/HT211289","https://usn.ubuntu.com/4352-1/","https://usn.ubuntu.com/4352-2/","https://www.debian.org/security/2020/dsa-4666","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-12243","description":"In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash)."}]},{"artifact":{"id":"3445236446ec4939","cpes":["cpe:2.3:a:krb5-locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5-locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"krb5-locales","purl":"pkg:deb/ubuntu/krb5-locales@1.16-2ubuntu0.1?arch=all&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/krb5-locales/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/krb5-locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/krb5-locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/krb5-locales.list"}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-28196","versionConstraint":"< 1.16-2ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-28196","fix":{"state":"fixed","versions":["1.16-2ubuntu0.2"],"available":[{"date":"2020-11-17","kind":"advisory","version":"1.16-2ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"risk":2.2085,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-28196"},"relatedVulnerabilities":[{"id":"CVE-2020-28196","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"urls":["https://github.com/krb5/krb5/commit/57415dda6cf04e73ffc3723be518eddfae599bfd","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/11/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/45KKOZQWIIIW5C45PJVGQ32AXBSYNBE7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73IGOG6CZAVMVNS4GGRMOLOZ7B6QVA7F/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPH2V3WSQTELROZK3GFCPQDOFLKIZ6H5/","https://security.gentoo.org/glsa/202011-17","https://security.netapp.com/advisory/ntap-20201202-0001/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://www.debian.org/security/2020/dsa-4795","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-28196","description":"MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit."}]},{"artifact":{"id":"f3fc35a2cb3401bd","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/ubuntu/libgssapi-krb5-2@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-28196","versionConstraint":"< 1.16-2ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-28196","fix":{"state":"fixed","versions":["1.16-2ubuntu0.2"],"available":[{"date":"2020-11-17","kind":"advisory","version":"1.16-2ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"risk":2.2085,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-28196"},"relatedVulnerabilities":[{"id":"CVE-2020-28196","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"urls":["https://github.com/krb5/krb5/commit/57415dda6cf04e73ffc3723be518eddfae599bfd","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/11/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/45KKOZQWIIIW5C45PJVGQ32AXBSYNBE7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73IGOG6CZAVMVNS4GGRMOLOZ7B6QVA7F/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPH2V3WSQTELROZK3GFCPQDOFLKIZ6H5/","https://security.gentoo.org/glsa/202011-17","https://security.netapp.com/advisory/ntap-20201202-0001/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://www.debian.org/security/2020/dsa-4795","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-28196","description":"MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit."}]},{"artifact":{"id":"ce64c2275844a0e2","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/ubuntu/libk5crypto3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-28196","versionConstraint":"< 1.16-2ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-28196","fix":{"state":"fixed","versions":["1.16-2ubuntu0.2"],"available":[{"date":"2020-11-17","kind":"advisory","version":"1.16-2ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"risk":2.2085,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-28196"},"relatedVulnerabilities":[{"id":"CVE-2020-28196","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"urls":["https://github.com/krb5/krb5/commit/57415dda6cf04e73ffc3723be518eddfae599bfd","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/11/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/45KKOZQWIIIW5C45PJVGQ32AXBSYNBE7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73IGOG6CZAVMVNS4GGRMOLOZ7B6QVA7F/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPH2V3WSQTELROZK3GFCPQDOFLKIZ6H5/","https://security.gentoo.org/glsa/202011-17","https://security.netapp.com/advisory/ntap-20201202-0001/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://www.debian.org/security/2020/dsa-4795","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-28196","description":"MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit."}]},{"artifact":{"id":"a0e77fe46f00e692","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/ubuntu/libkrb5-3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-28196","versionConstraint":"< 1.16-2ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-28196","fix":{"state":"fixed","versions":["1.16-2ubuntu0.2"],"available":[{"date":"2020-11-17","kind":"advisory","version":"1.16-2ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"risk":2.2085,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-28196"},"relatedVulnerabilities":[{"id":"CVE-2020-28196","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"urls":["https://github.com/krb5/krb5/commit/57415dda6cf04e73ffc3723be518eddfae599bfd","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/11/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/45KKOZQWIIIW5C45PJVGQ32AXBSYNBE7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73IGOG6CZAVMVNS4GGRMOLOZ7B6QVA7F/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPH2V3WSQTELROZK3GFCPQDOFLKIZ6H5/","https://security.gentoo.org/glsa/202011-17","https://security.netapp.com/advisory/ntap-20201202-0001/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://www.debian.org/security/2020/dsa-4795","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-28196","description":"MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit."}]},{"artifact":{"id":"402827dd4cb6593f","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/ubuntu/libkrb5support0@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-28196","versionConstraint":"< 1.16-2ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-28196","fix":{"state":"fixed","versions":["1.16-2ubuntu0.2"],"available":[{"date":"2020-11-17","kind":"advisory","version":"1.16-2ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"risk":2.2085,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-28196"},"relatedVulnerabilities":[{"id":"CVE-2020-28196","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"urls":["https://github.com/krb5/krb5/commit/57415dda6cf04e73ffc3723be518eddfae599bfd","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/11/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/45KKOZQWIIIW5C45PJVGQ32AXBSYNBE7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73IGOG6CZAVMVNS4GGRMOLOZ7B6QVA7F/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPH2V3WSQTELROZK3GFCPQDOFLKIZ6H5/","https://security.gentoo.org/glsa/202011-17","https://security.netapp.com/advisory/ntap-20201202-0001/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://www.debian.org/security/2020/dsa-4795","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-28196","description":"MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35603","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35603","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-35603","date":"2026-10-08","epss":0.04411,"percentile":0.91088}],"risk":2.2055000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35603"},"relatedVulnerabilities":[{"id":"CVE-2021-35603","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35603","date":"2026-10-08","epss":0.04411,"percentile":0.91088}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-5000","https://www.debian.org/security/2021/dsa-5012","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35603","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"7f8a327c8749dc34","cpes":["cpe:2.3:a:org.hibernate.core:hibernate-core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.core:hibernate_core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-core:hibernate-core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-core:hibernate_core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_core:hibernate-core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_core:hibernate_core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-org:hibernate-core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-org:hibernate_core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_org:hibernate-core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_org:hibernate_core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate:hibernate-core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate:hibernate_core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:hibernate-core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:hibernate_core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.core:core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:core:hibernate-core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:core:hibernate_core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-core:core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_core:core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-org:core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_org:core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate:core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:core:5.2.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:core:core:5.2.17.Final:*:*:*:*:*:*:*"],"name":"hibernate-core","purl":"pkg:maven/org.hibernate/hibernate-core@5.2.17.Final","type":"java-archive","version":"5.2.17.Final","language":"java","licenses":[],"metadata":{"pomGroupID":"org.hibernate","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/hibernate-core-5.2.17.Final.jar","manifestName":"","pomArtifactID":"hibernate-core","archiveDigests":[{"value":"f2dc36470e7a2ffcf6106bb1625ecf5b54bb5f65","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/hibernate-core-5.2.17.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.3.20.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j8jw-g6fq-mp7h","versionConstraint":"<5.3.20.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.hibernate:hibernate-core","version":"5.2.17.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j8jw-g6fq-mp7h","fix":{"state":"fixed","versions":["5.3.20.Final"],"available":[{"date":"2022-11-24","kind":"first-observed","version":"5.3.20.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25638","cwe":"CWE-89","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-25638","cwe":"CWE-89","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-25638","date":"2026-10-08","epss":0.02929,"percentile":0.86672}],"risk":2.182105,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-25638","https://bugzilla.redhat.com/show_bug.cgi?id=1881353","https://lists.debian.org/debian-lts-announce/2021/01/msg00000.html","https://www.debian.org/security/2021/dsa-4908","https://lists.apache.org/thread.html/r833c1276e41334fa675848a08daf0c61f39009f9f9a400d9f7006d44@%3Cdev.turbine.apache.org%3E","https://lists.apache.org/thread.html/rf2378209c676a28b71f9b604a3b3517c448540b85367160e558ef9df@%3Ccommits.turbine.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/hibernate/hibernate-orm/commit/36ebf7d3836e83e99f2a91777b5389e1daf1f2b7","https://github.com/hibernate/hibernate-orm/commit/59fede7acaaa1579b561407aefa582311f7ebe78","https://github.com/hibernate/hibernate-orm/commit/d22bbb5c339c9df7712c3365bb1df97c91b35ec5"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j8jw-g6fq-mp7h","description":"SQL injection in hibernate-core"},"relatedVulnerabilities":[{"id":"CVE-2020-25638","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25638","cwe":"CWE-89","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-25638","cwe":"CWE-89","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-25638","date":"2026-10-08","epss":0.02929,"percentile":0.86672}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1881353","https://lists.apache.org/thread.html/r833c1276e41334fa675848a08daf0c61f39009f9f9a400d9f7006d44%40%3Cdev.turbine.apache.org%3E","https://lists.apache.org/thread.html/rf2378209c676a28b71f9b604a3b3517c448540b85367160e558ef9df%40%3Ccommits.turbine.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/01/msg00000.html","https://www.debian.org/security/2021/dsa-4908","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-25638","description":"A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.4+11-1ubuntu2~18.04.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2762","versionConstraint":"< 11.0.4+11-1ubuntu2~18.04.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2762","fix":{"state":"fixed","versions":["11.0.4+11-1ubuntu2~18.04.3"],"available":[{"date":"2019-07-31","kind":"advisory","version":"11.0.4+11-1ubuntu2~18.04.3"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2762","date":"2026-10-08","epss":0.04351,"percentile":0.90975}],"risk":2.1755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2762"},"relatedVulnerabilities":[{"id":"CVE-2019-2762","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2762","date":"2026-10-08","epss":0.04351,"percentile":0.90975}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00038.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00044.html","http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://access.redhat.com/errata/RHSA-2019:2494","https://access.redhat.com/errata/RHSA-2019:2495","https://access.redhat.com/errata/RHSA-2019:2585","https://access.redhat.com/errata/RHSA-2019:2590","https://access.redhat.com/errata/RHSA-2019:2592","https://access.redhat.com/errata/RHSA-2019:2737","https://kc.mcafee.com/corporate/index?page=content&id=SB10300","https://lists.debian.org/debian-lts-announce/2019/08/msg00020.html","https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03977en_us","https://usn.ubuntu.com/4080-1/","https://usn.ubuntu.com/4083-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2762","description":"Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.4+11-1ubuntu2~18.04.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2769","versionConstraint":"< 11.0.4+11-1ubuntu2~18.04.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2769","fix":{"state":"fixed","versions":["11.0.4+11-1ubuntu2~18.04.3"],"available":[{"date":"2019-07-31","kind":"advisory","version":"11.0.4+11-1ubuntu2~18.04.3"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2769","date":"2026-10-08","epss":0.04351,"percentile":0.90975}],"risk":2.1755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2769"},"relatedVulnerabilities":[{"id":"CVE-2019-2769","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2769","date":"2026-10-08","epss":0.04351,"percentile":0.90975}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00038.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00044.html","http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://access.redhat.com/errata/RHSA-2019:2494","https://access.redhat.com/errata/RHSA-2019:2495","https://access.redhat.com/errata/RHSA-2019:2585","https://access.redhat.com/errata/RHSA-2019:2590","https://access.redhat.com/errata/RHSA-2019:2592","https://access.redhat.com/errata/RHSA-2019:2737","https://kc.mcafee.com/corporate/index?page=content&id=SB10300","https://lists.debian.org/debian-lts-announce/2019/08/msg00020.html","https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03977en_us","https://usn.ubuntu.com/4080-1/","https://usn.ubuntu.com/4083-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2769","description":"Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.8+10-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14621","versionConstraint":"< 11.0.8+10-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14621","fix":{"state":"fixed","versions":["11.0.8+10-0ubuntu1~18.04.1"],"available":[{"date":"2020-07-23","kind":"advisory","version":"11.0.8+10-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14621","date":"2026-10-08","epss":0.0435,"percentile":0.90973}],"risk":2.175,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14621"},"relatedVulnerabilities":[{"id":"CVE-2020-14621","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14621","date":"2026-10-08","epss":0.0435,"percentile":0.90973}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html","http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://kc.mcafee.com/corporate/index?page=content&id=SB10332","https://lists.apache.org/thread.html/rf96c5afb26b596b4b97883aa90b6c0b0fc4c26aaeea7123c21912103%40%3Cj-users.xerces.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/08/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CFJPOYF3CWYEPCDOAOCNFJTQIKKWPHW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFZ36XIW5ENQAW6BB7WHRFFTTJX7KGMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/","https://security.gentoo.org/glsa/202008-24","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200717-0005/","https://usn.ubuntu.com/4433-1/","https://usn.ubuntu.com/4453-1/","https://www.debian.org/security/2020/dsa-4734","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14621","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"0c17bed56057f9e7","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.1?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36225","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36225","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36225","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36225","date":"2026-10-08","epss":0.043,"percentile":0.90884}],"risk":2.15,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36225"},"relatedVulnerabilities":[{"id":"CVE-2020-36225","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36225","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36225","date":"2026-10-08","epss":0.043,"percentile":0.90884}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9412","https://git.openldap.org/openldap/openldap/-/commit/554dff1927176579d652f2fe60c90e9abbad4c65","https://git.openldap.org/openldap/openldap/-/commit/5a2017d4e61a6ddc4dcb4415028e0d08eb6bca26","https://git.openldap.org/openldap/openldap/-/commit/c0b61a9486508e5202aa2e0cfb68c9813731b439","https://git.openldap.org/openldap/openldap/-/commit/d169e7958a3e0dc70f59c8374bf8a59833b7bdd8","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36225","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service."}]},{"artifact":{"id":"d1ea226d64532803","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.1?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36225","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36225","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36225","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36225","date":"2026-10-08","epss":0.043,"percentile":0.90884}],"risk":2.15,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36225"},"relatedVulnerabilities":[{"id":"CVE-2020-36225","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36225","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36225","date":"2026-10-08","epss":0.043,"percentile":0.90884}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9412","https://git.openldap.org/openldap/openldap/-/commit/554dff1927176579d652f2fe60c90e9abbad4c65","https://git.openldap.org/openldap/openldap/-/commit/5a2017d4e61a6ddc4dcb4415028e0d08eb6bca26","https://git.openldap.org/openldap/openldap/-/commit/c0b61a9486508e5202aa2e0cfb68c9813731b439","https://git.openldap.org/openldap/openldap/-/commit/d169e7958a3e0dc70f59c8374bf8a59833b7bdd8","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36225","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service."}]},{"artifact":{"id":"0c17bed56057f9e7","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.1?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36223","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36223","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36223","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36223","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36223","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"risk":2.15,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36223"},"relatedVulnerabilities":[{"id":"CVE-2020-36223","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36223","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36223","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36223","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9408","https://git.openldap.org/openldap/openldap/-/commit/21981053a1195ae1555e23df4d9ac68d34ede9dd","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36223","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read)."}]},{"artifact":{"id":"0c17bed56057f9e7","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.1?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36224","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36224","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36224","cwe":"CWE-763","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36224","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"risk":2.15,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36224"},"relatedVulnerabilities":[{"id":"CVE-2020-36224","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36224","cwe":"CWE-763","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36224","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9409","https://git.openldap.org/openldap/openldap/-/commit/554dff1927176579d652f2fe60c90e9abbad4c65","https://git.openldap.org/openldap/openldap/-/commit/5a2017d4e61a6ddc4dcb4415028e0d08eb6bca26","https://git.openldap.org/openldap/openldap/-/commit/c0b61a9486508e5202aa2e0cfb68c9813731b439","https://git.openldap.org/openldap/openldap/-/commit/d169e7958a3e0dc70f59c8374bf8a59833b7bdd8","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36224","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service."}]},{"artifact":{"id":"0c17bed56057f9e7","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.1?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36229","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36229","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36229","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36229","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"risk":2.15,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36229"},"relatedVulnerabilities":[{"id":"CVE-2020-36229","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36229","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36229","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9425","https://git.openldap.org/openldap/openldap/-/commit/4bdfffd2889c0c5cdf58bebafbdc8fce4bb2bff0","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36229","description":"A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service."}]},{"artifact":{"id":"d1ea226d64532803","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.1?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36223","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36223","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36223","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36223","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36223","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"risk":2.15,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36223"},"relatedVulnerabilities":[{"id":"CVE-2020-36223","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36223","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36223","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36223","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9408","https://git.openldap.org/openldap/openldap/-/commit/21981053a1195ae1555e23df4d9ac68d34ede9dd","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36223","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read)."}]},{"artifact":{"id":"d1ea226d64532803","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.1?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36224","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36224","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36224","cwe":"CWE-763","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36224","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"risk":2.15,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36224"},"relatedVulnerabilities":[{"id":"CVE-2020-36224","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36224","cwe":"CWE-763","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36224","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9409","https://git.openldap.org/openldap/openldap/-/commit/554dff1927176579d652f2fe60c90e9abbad4c65","https://git.openldap.org/openldap/openldap/-/commit/5a2017d4e61a6ddc4dcb4415028e0d08eb6bca26","https://git.openldap.org/openldap/openldap/-/commit/c0b61a9486508e5202aa2e0cfb68c9813731b439","https://git.openldap.org/openldap/openldap/-/commit/d169e7958a3e0dc70f59c8374bf8a59833b7bdd8","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36224","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service."}]},{"artifact":{"id":"d1ea226d64532803","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.1?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36229","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36229","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36229","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36229","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"risk":2.15,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36229"},"relatedVulnerabilities":[{"id":"CVE-2020-36229","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36229","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36229","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9425","https://git.openldap.org/openldap/openldap/-/commit/4bdfffd2889c0c5cdf58bebafbdc8fce4bb2bff0","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36229","description":"A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.6+10-1ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-2601","versionConstraint":"< 11.0.6+10-1ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-2601","fix":{"state":"fixed","versions":["11.0.6+10-1ubuntu1~18.04.1"],"available":[{"date":"2020-01-28","kind":"advisory","version":"11.0.6+10-1ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-2601","date":"2026-10-08","epss":0.04299,"percentile":0.90881}],"risk":2.1495,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-2601"},"relatedVulnerabilities":[{"id":"CVE-2020-2601","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-2601","date":"2026-10-08","epss":0.04299,"percentile":0.90881}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00050.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00060.html","https://access.redhat.com/errata/RHSA-2020:0122","https://access.redhat.com/errata/RHSA-2020:0128","https://access.redhat.com/errata/RHSA-2020:0157","https://access.redhat.com/errata/RHSA-2020:0196","https://access.redhat.com/errata/RHSA-2020:0202","https://access.redhat.com/errata/RHSA-2020:0231","https://access.redhat.com/errata/RHSA-2020:0232","https://access.redhat.com/errata/RHSA-2020:0541","https://access.redhat.com/errata/RHSA-2020:0632","https://lists.debian.org/debian-lts-announce/2020/02/msg00034.html","https://seclists.org/bugtraq/2020/Feb/22","https://seclists.org/bugtraq/2020/Jan/24","https://security.gentoo.org/glsa/202101-19","https://security.netapp.com/advisory/ntap-20200122-0003/","https://usn.ubuntu.com/4257-1/","https://www.debian.org/security/2020/dsa-4605","https://www.debian.org/security/2020/dsa-4621","https://www.oracle.com/security-alerts/cpujan2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-2601","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N)."}]},{"artifact":{"id":"88bdd6da7cccc159","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20843","versionConstraint":"< 2.2.5-3ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-20843","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.1"],"available":[{"date":"2019-06-26","kind":"advisory","version":"2.2.5-3ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-20843","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-20843","cwe":"CWE-611","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-20843","date":"2026-10-08","epss":0.07107,"percentile":0.94086}],"risk":2.1320999999999994,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-20843"},"relatedVulnerabilities":[{"id":"CVE-2018-20843","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.8,"impactScore":6.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20843","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-20843","cwe":"CWE-611","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-20843","date":"2026-10-08","epss":0.07107,"percentile":0.94086}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00039.html","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5226","https://github.com/libexpat/libexpat/blob/R_2_2_7/expat/Changes","https://github.com/libexpat/libexpat/issues/186","https://github.com/libexpat/libexpat/pull/262","https://github.com/libexpat/libexpat/pull/262/commits/11f8838bf99ea0a6f0b76f9760c43704d00c4ff6","https://lists.debian.org/debian-lts-announce/2019/06/msg00028.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CEJJSQSG3KSUQY4FPVHZ7ZTT7FORMFVD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IDAUGEB3TUP6NEKJDBUBZX7N5OAUOOOK/","https://seclists.org/bugtraq/2019/Jun/39","https://security.gentoo.org/glsa/201911-08","https://security.netapp.com/advisory/ntap-20190703-0001/","https://support.f5.com/csp/article/K51011533","https://usn.ubuntu.com/4040-1/","https://usn.ubuntu.com/4040-2/","https://www.debian.org/security/2019/dsa-4472","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-11"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20843","description":"In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-2341","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-2341","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-2341","date":"2026-10-08","epss":0.04238,"percentile":0.90772}],"risk":2.119,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-2341"},"relatedVulnerabilities":[{"id":"CVE-2021-2341","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-2341","date":"2026-10-08","epss":0.04238,"percentile":0.90772}],"urls":["https://lists.debian.org/debian-lts-announce/2021/08/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A4TTUHVQF2MGUTP6GTCXLZS4GXK3XUWC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N57OFX5EJKHHDW4WAOBZFWA5CL4VIIK5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PJJ75FHSUZGWPV4UJTSMQHWLOQ77LHTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VTRQIXB52KIXUAO6JBYUKYWXST2NKNAK/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20210723-0002/","https://www.debian.org/security/2021/dsa-4946","https://www.oracle.com/security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-2341","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"0c17bed56057f9e7","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.1?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36226","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36226","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"epss":[{"cve":"CVE-2020-36226","date":"2026-10-08","epss":0.04184,"percentile":0.90665}],"risk":2.092,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36226"},"relatedVulnerabilities":[{"id":"CVE-2020-36226","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-36226","date":"2026-10-08","epss":0.04184,"percentile":0.90665}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9413","https://git.openldap.org/openldap/openldap/-/commit/554dff1927176579d652f2fe60c90e9abbad4c65","https://git.openldap.org/openldap/openldap/-/commit/5a2017d4e61a6ddc4dcb4415028e0d08eb6bca26","https://git.openldap.org/openldap/openldap/-/commit/c0b61a9486508e5202aa2e0cfb68c9813731b439","https://git.openldap.org/openldap/openldap/-/commit/d169e7958a3e0dc70f59c8374bf8a59833b7bdd8","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36226","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service."}]},{"artifact":{"id":"d1ea226d64532803","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.1:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.1?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.1","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36226","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36226","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"epss":[{"cve":"CVE-2020-36226","date":"2026-10-08","epss":0.04184,"percentile":0.90665}],"risk":2.092,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36226"},"relatedVulnerabilities":[{"id":"CVE-2020-36226","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-36226","date":"2026-10-08","epss":0.04184,"percentile":0.90665}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9413","https://git.openldap.org/openldap/openldap/-/commit/554dff1927176579d652f2fe60c90e9abbad4c65","https://git.openldap.org/openldap/openldap/-/commit/5a2017d4e61a6ddc4dcb4415028e0d08eb6bca26","https://git.openldap.org/openldap/openldap/-/commit/c0b61a9486508e5202aa2e0cfb68c9813731b439","https://git.openldap.org/openldap/openldap/-/commit/d169e7958a3e0dc70f59c8374bf8a59833b7bdd8","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36226","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service."}]},{"artifact":{"id":"0b1c74783f88c915","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.22.0-1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20505","versionConstraint":"< 3.22.0-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-20505","fix":{"state":"fixed","versions":["3.22.0-1ubuntu0.1"],"available":[{"date":"2019-06-19","kind":"advisory","version":"3.22.0-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-20505","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20505","date":"2026-10-08","epss":0.06952,"percentile":0.93959}],"risk":2.0856,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-20505"},"relatedVulnerabilities":[{"id":"CVE-2018-20505","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20505","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20505","date":"2026-10-08","epss":0.06952,"percentile":0.93959}],"urls":["http://seclists.org/fulldisclosure/2019/Jan/62","http://seclists.org/fulldisclosure/2019/Jan/64","http://seclists.org/fulldisclosure/2019/Jan/66","http://seclists.org/fulldisclosure/2019/Jan/67","http://seclists.org/fulldisclosure/2019/Jan/68","http://seclists.org/fulldisclosure/2019/Jan/69","http://www.securityfocus.com/bid/106698","https://seclists.org/bugtraq/2019/Jan/28","https://seclists.org/bugtraq/2019/Jan/29","https://seclists.org/bugtraq/2019/Jan/31","https://seclists.org/bugtraq/2019/Jan/32","https://seclists.org/bugtraq/2019/Jan/33","https://seclists.org/bugtraq/2019/Jan/39","https://security.netapp.com/advisory/ntap-20190502-0004/","https://sqlite.org/src/info/1a84668dcfdebaf12415d","https://support.apple.com/kb/HT209443","https://support.apple.com/kb/HT209446","https://support.apple.com/kb/HT209447","https://support.apple.com/kb/HT209448","https://support.apple.com/kb/HT209450","https://support.apple.com/kb/HT209451","https://usn.ubuntu.com/4019-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20505","description":"SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.16+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21540","versionConstraint":"< 11.0.16+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21540","fix":{"state":"fixed","versions":["11.0.16+8-0ubuntu1~18.04"],"available":[{"date":"2022-08-04","kind":"advisory","version":"11.0.16+8-0ubuntu1~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21540","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21540","date":"2026-10-08","epss":0.04167,"percentile":0.90627}],"risk":2.0835,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21540"},"relatedVulnerabilities":[{"id":"CVE-2022-21540","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21540","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21540","date":"2026-10-08","epss":0.04167,"percentile":0.90627}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4YNJSJ64NPCNKFPNBYITNZU5H3L4D6L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5OZNAZJ4YHLOKRRRZSWRT5OJ25E4XLM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JN3EVGR7FD3ZLV5SBTJXUIDCMSK4QUE2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KO3DXNKZ4EU3UZBT6AAR4XRKCD73KLMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3XPOTPPBZIPFBZHQE5E7OW6PDACUMCJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YULPNO3PAWMEQQZV2C54I3H3ZOXFZUTB/","https://security.gentoo.org/glsa/202401-25","https://security.netapp.com/advisory/ntap-20220729-0009/","https://www.debian.org/security/2022/dsa-5188","https://www.debian.org/security/2022/dsa-5192","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21540","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"f2b3aae4ffb91c19","cpes":["cpe:2.3:a:org.yaml.snakeyaml:snakeyaml:1.19:*:*:*:*:*:*:*","cpe:2.3:a:snakeyaml:snakeyaml:1.19:*:*:*:*:*:*:*","cpe:2.3:a:org.yaml:snakeyaml:1.19:*:*:*:*:*:*:*","cpe:2.3:a:yaml:snakeyaml:1.19:*:*:*:*:*:*:*"],"name":"snakeyaml","purl":"pkg:maven/org.yaml/snakeyaml@1.19","type":"java-archive","version":"1.19","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.yaml","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/snakeyaml-1.19.jar","manifestName":"","pomArtifactID":"snakeyaml","archiveDigests":[{"value":"2d998d3d674b172a588e54ab619854d073f555b5","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/snakeyaml-1.19.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.31"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3mc7-4q67-w48m","versionConstraint":"<1.31 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.yaml:snakeyaml","version":"1.19"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-3mc7-4q67-w48m","fix":{"state":"fixed","versions":["1.31"],"available":[{"date":"2022-09-12","kind":"first-observed","version":"1.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25857","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-25857","date":"2026-10-08","epss":0.02749,"percentile":0.85777}],"risk":2.06175,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-25857","https://github.com/snakeyaml/snakeyaml/commit/fc300780da21f4bb92c148bc90257201220cf174","https://bitbucket.org/snakeyaml/snakeyaml/commits/fc300780da21f4bb92c148bc90257201220cf174","https://bitbucket.org/snakeyaml/snakeyaml/issues/525","https://security.snyk.io/vuln/SNYK-JAVA-ORGYAML-2806360","https://lists.debian.org/debian-lts-announce/2022/10/msg00001.html","https://security.netapp.com/advisory/ntap-20240315-0010"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3mc7-4q67-w48m","description":"Uncontrolled Resource Consumption in snakeyaml"},"relatedVulnerabilities":[{"id":"CVE-2022-25857","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25857","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-25857","date":"2026-10-08","epss":0.02749,"percentile":0.85777}],"urls":["https://bitbucket.org/snakeyaml/snakeyaml/commits/fc300780da21f4bb92c148bc90257201220cf174","https://bitbucket.org/snakeyaml/snakeyaml/issues/525","https://github.com/snakeyaml/snakeyaml/commit/fc300780da21f4bb92c148bc90257201220cf174","https://lists.debian.org/debian-lts-announce/2022/10/msg00001.html","https://security.netapp.com/advisory/ntap-20240315-0010/","https://security.snyk.io/vuln/SNYK-JAVA-ORGYAML-2806360"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25857","description":"The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.7+10-2ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-2805","versionConstraint":"< 11.0.7+10-2ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-2805","fix":{"state":"fixed","versions":["11.0.7+10-2ubuntu2~18.04"],"available":[{"date":"2020-04-22","kind":"advisory","version":"11.0.7+10-2ubuntu2~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2020-2805","date":"2026-10-08","epss":0.04051,"percentile":0.90378}],"risk":2.0255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-2805"},"relatedVulnerabilities":[{"id":"CVE-2020-2805","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"impactScore":6.5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-2805","date":"2026-10-08","epss":0.04051,"percentile":0.90378}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00000.html","http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00023.html","http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00048.html","https://lists.debian.org/debian-lts-announce/2020/04/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CKAV6KFFAEANXAN73AFTGU7Z6YNRWCXQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7VHC4EW36KZEIDQ56RPCWBZCQELFFKN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NYHHHZRHXCBGRHGE5UP7UEB4IZ2QX536/","https://security.gentoo.org/glsa/202006-22","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200416-0004/","https://usn.ubuntu.com/4337-1/","https://www.debian.org/security/2020/dsa-4662","https://www.debian.org/security/2020/dsa-4668","https://www.oracle.com/security-alerts/cpuapr2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-2805","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.15+10-0ubuntu0.18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21476","versionConstraint":"< 11.0.15+10-0ubuntu0.18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21476","fix":{"state":"fixed","versions":["11.0.15+10-0ubuntu0.18.04.1"],"available":[{"date":"2022-04-26","kind":"advisory","version":"11.0.15+10-0ubuntu0.18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21476","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21476","date":"2026-10-08","epss":0.04046,"percentile":0.90365}],"risk":2.023,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21476"},"relatedVulnerabilities":[{"id":"CVE-2022-21476","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21476","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21476","date":"2026-10-08","epss":0.04046,"percentile":0.90365}],"urls":["https://lists.debian.org/debian-lts-announce/2022/05/msg00017.html","https://security.netapp.com/advisory/ntap-20220429-0006/","https://www.debian.org/security/2022/dsa-5128","https://www.debian.org/security/2022/dsa-5131","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21476","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)."}]},{"artifact":{"id":"81f8e17aa26e6e42","cpes":["cpe:2.3:a:org.springframework:spring-web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-web:spring-web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-web:spring_web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_web:spring-web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_web:spring_web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-web:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_web:5.0.8.RELEASE:*:*:*:*:*:*:*"],"name":"spring-web","purl":"pkg:maven/org.springframework/spring-web@5.0.8.RELEASE","type":"java-archive","version":"5.0.8.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-web-5.0.8.RELEASE.jar","manifestName":"","pomArtifactID":"spring-web","archiveDigests":[{"value":"fa43cdadb4ab2491fd1d0ddb06c0808e4b60fc85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-web-5.0.8.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.3.33"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hgjh-9rj2-g67j","versionConstraint":"<5.3.33 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-web","version":"5.0.8.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hgjh-9rj2-g67j","fix":{"state":"fixed","versions":["5.3.33"],"available":[{"date":"2024-03-19","kind":"first-observed","version":"5.3.33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-22259","cwe":"CWE-601","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-22259","date":"2026-10-08","epss":0.02573,"percentile":0.84713}],"risk":2.00694,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-22259","https://spring.io/security/cve-2024-22259","https://github.com/spring-projects/spring-framework/commit/297cbae2990e1413537c55845a7e0ea0ffd9f9bb","https://github.com/spring-projects/spring-framework/commit/381f790329a48b74c2a49fc1384dd68ca9153501","https://github.com/spring-projects/spring-framework/commit/f2fd2f12269c6a781c5b2c20b3c24141055a3d68","https://security.netapp.com/advisory/ntap-20240524-0002"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hgjh-9rj2-g67j","description":"Spring Framework URL Parsing with Host Validation Vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2024-22259","cvss":[{"type":"Secondary","source":"security@vmware.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-22259","cwe":"CWE-601","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-22259","date":"2026-10-08","epss":0.02573,"percentile":0.84713}],"urls":["https://security.netapp.com/advisory/ntap-20240524-0002/","https://spring.io/security/cve-2024-22259"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-22259","description":"Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a  open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.\n\nThis is the same as  CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-2388","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-2388","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-2388","date":"2026-10-08","epss":0.04008,"percentile":0.90288}],"risk":2.004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-2388"},"relatedVulnerabilities":[{"id":"CVE-2021-2388","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"impactScore":6.5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-2388","date":"2026-10-08","epss":0.04008,"percentile":0.90288}],"urls":["https://lists.debian.org/debian-lts-announce/2021/08/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20210723-0002/","https://www.debian.org/security/2021/dsa-4946","https://www.oracle.com/security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-2388","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)."}]},{"artifact":{"id":"88bdd6da7cccc159","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23990","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-23990","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-23990","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23990","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23990","date":"2026-10-08","epss":0.03992,"percentile":0.90252}],"risk":1.9959999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23990"},"relatedVulnerabilities":[{"id":"CVE-2022-23990","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23990","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23990","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23990","date":"2026-10-08","epss":0.03992,"percentile":0.90252}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/551","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/34NXVL2RZC2YZRV74ZQ3RNFB7WCEUP7D/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7FF2UH7MPXKTADYSJUAHI2Y5UHBSHUH/","https://security.gentoo.org/glsa/202209-24","https://www.debian.org/security/2022/dsa-5073","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.tenable.com/security/tns-2022-05"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23990","description":"Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.5.96"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-fccv-jmmp-qg76","versionConstraint":">=8.5.0,<8.5.96 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-fccv-jmmp-qg76","fix":{"state":"fixed","versions":["8.5.96"],"available":[{"date":"2023-12-22","kind":"first-observed","version":"8.5.96"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-46589","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2023-46589","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-46589","date":"2026-10-08","epss":0.02651,"percentile":0.8519}],"risk":1.9882499999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-46589","https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr","http://www.openwall.com/lists/oss-security/2023/11/28/2","https://github.com/apache/tomcat/commit/6f181e1062a472bc5f0234980f66cbde42c1041b","https://github.com/apache/tomcat/commit/7a2d8818fcea0b51747a67af9510ce7977245ebd","https://github.com/apache/tomcat/commit/aa92971e879a519384c517febc39fd04c48d4642","https://github.com/apache/tomcat/commit/b5776d769bffeade865061bc8ecbeb2b56167b08","https://tomcat.apache.org/security-10.html","https://tomcat.apache.org/security-11.html","https://tomcat.apache.org/security-8.html","https://tomcat.apache.org/security-9.html","https://www.openwall.com/lists/oss-security/2023/11/28/2","https://lists.debian.org/debian-lts-announce/2024/01/msg00001.html","https://security.netapp.com/advisory/ntap-20231214-0009"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-fccv-jmmp-qg76","description":"Apache Tomcat Improper Input Validation vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2023-46589","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-46589","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2023-46589","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-46589","date":"2026-10-08","epss":0.02651,"percentile":0.8519}],"urls":["https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr","https://www.openwall.com/lists/oss-security/2023/11/28/2","https://lists.debian.org/debian-lts-announce/2024/01/msg00001.html","https://security.netapp.com/advisory/ntap-20231214-0009/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-46589","description":"Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single \nrequest as multiple requests leading to the possibility of request \nsmuggling when behind a reverse proxy.\n\n\nOlder, EOL versions may also be affected.\n\n\nUsers are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-8492","versionConstraint":"< 2.7.17-1~18.04ubuntu1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-8492","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1"],"available":[{"date":"2020-04-21","kind":"advisory","version":"2.7.17-1~18.04ubuntu1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-8492","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-8492","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-8492","date":"2026-10-08","epss":0.06617,"percentile":0.9369}],"risk":1.9851,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-8492"},"relatedVulnerabilities":[{"id":"CVE-2020-8492","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8492","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-8492","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-8492","date":"2026-10-08","epss":0.06617,"percentile":0.9369}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html","https://bugs.python.org/issue39503","https://github.com/python/cpython/pull/18284","https://lists.apache.org/thread.html/rdb31a608dd6758c6093fd645aea3fbf022dd25b37109b6aaea5bc0b5%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rfec113c733162b39633fd86a2d0f34bf42ac35f711b3ec1835c774da%40%3Ccommits.cassandra.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WOKDEXLYW5UQ4S7PA7E37IITOC7C56J/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5NSAX4SC3V64PGZUPH7PRDLSON34Q5A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APGWEMYZIY5VHLCSZ3HD67PA5Z2UQFGH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UESGYI5XDAHJBATEZN3MHNDUBDH47AS6/","https://python-security.readthedocs.io/vuln/urllib-basic-auth-regex.html","https://security.gentoo.org/glsa/202005-09","https://security.netapp.com/advisory/ntap-20200221-0001/","https://usn.ubuntu.com/4333-1/","https://usn.ubuntu.com/4333-2/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8492","description":"Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-8492","versionConstraint":"< 2.7.17-1~18.04ubuntu1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-8492","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1"],"available":[{"date":"2020-04-21","kind":"advisory","version":"2.7.17-1~18.04ubuntu1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-8492","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-8492","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-8492","date":"2026-10-08","epss":0.06617,"percentile":0.9369}],"risk":1.9851,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-8492"},"relatedVulnerabilities":[{"id":"CVE-2020-8492","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8492","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-8492","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-8492","date":"2026-10-08","epss":0.06617,"percentile":0.9369}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html","https://bugs.python.org/issue39503","https://github.com/python/cpython/pull/18284","https://lists.apache.org/thread.html/rdb31a608dd6758c6093fd645aea3fbf022dd25b37109b6aaea5bc0b5%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rfec113c733162b39633fd86a2d0f34bf42ac35f711b3ec1835c774da%40%3Ccommits.cassandra.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WOKDEXLYW5UQ4S7PA7E37IITOC7C56J/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5NSAX4SC3V64PGZUPH7PRDLSON34Q5A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APGWEMYZIY5VHLCSZ3HD67PA5Z2UQFGH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UESGYI5XDAHJBATEZN3MHNDUBDH47AS6/","https://python-security.readthedocs.io/vuln/urllib-basic-auth-regex.html","https://security.gentoo.org/glsa/202005-09","https://security.netapp.com/advisory/ntap-20200221-0001/","https://usn.ubuntu.com/4333-1/","https://usn.ubuntu.com/4333-2/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8492","description":"Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-8492","versionConstraint":"< 2.7.17-1~18.04ubuntu1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-8492","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1"],"available":[{"date":"2020-04-21","kind":"advisory","version":"2.7.17-1~18.04ubuntu1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-8492","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-8492","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-8492","date":"2026-10-08","epss":0.06617,"percentile":0.9369}],"risk":1.9851,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-8492"},"relatedVulnerabilities":[{"id":"CVE-2020-8492","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8492","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-8492","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-8492","date":"2026-10-08","epss":0.06617,"percentile":0.9369}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html","https://bugs.python.org/issue39503","https://github.com/python/cpython/pull/18284","https://lists.apache.org/thread.html/rdb31a608dd6758c6093fd645aea3fbf022dd25b37109b6aaea5bc0b5%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rfec113c733162b39633fd86a2d0f34bf42ac35f711b3ec1835c774da%40%3Ccommits.cassandra.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WOKDEXLYW5UQ4S7PA7E37IITOC7C56J/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5NSAX4SC3V64PGZUPH7PRDLSON34Q5A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APGWEMYZIY5VHLCSZ3HD67PA5Z2UQFGH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UESGYI5XDAHJBATEZN3MHNDUBDH47AS6/","https://python-security.readthedocs.io/vuln/urllib-basic-auth-regex.html","https://security.gentoo.org/glsa/202005-09","https://security.netapp.com/advisory/ntap-20200221-0001/","https://usn.ubuntu.com/4333-1/","https://usn.ubuntu.com/4333-2/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8492","description":"Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-8492","versionConstraint":"< 2.7.17-1~18.04ubuntu1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-8492","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1"],"available":[{"date":"2020-04-21","kind":"advisory","version":"2.7.17-1~18.04ubuntu1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-8492","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-8492","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-8492","date":"2026-10-08","epss":0.06617,"percentile":0.9369}],"risk":1.9851,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-8492"},"relatedVulnerabilities":[{"id":"CVE-2020-8492","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8492","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-8492","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-8492","date":"2026-10-08","epss":0.06617,"percentile":0.9369}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html","https://bugs.python.org/issue39503","https://github.com/python/cpython/pull/18284","https://lists.apache.org/thread.html/rdb31a608dd6758c6093fd645aea3fbf022dd25b37109b6aaea5bc0b5%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rfec113c733162b39633fd86a2d0f34bf42ac35f711b3ec1835c774da%40%3Ccommits.cassandra.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WOKDEXLYW5UQ4S7PA7E37IITOC7C56J/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5NSAX4SC3V64PGZUPH7PRDLSON34Q5A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APGWEMYZIY5VHLCSZ3HD67PA5Z2UQFGH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UESGYI5XDAHJBATEZN3MHNDUBDH47AS6/","https://python-security.readthedocs.io/vuln/urllib-basic-auth-regex.html","https://security.gentoo.org/glsa/202005-09","https://security.netapp.com/advisory/ntap-20200221-0001/","https://usn.ubuntu.com/4333-1/","https://usn.ubuntu.com/4333-2/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8492","description":"Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking."}]},{"artifact":{"id":"0b1c74783f88c915","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.22.0-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-13734","versionConstraint":"< 3.22.0-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-13734","fix":{"state":"fixed","versions":["3.22.0-1ubuntu0.3"],"available":[{"date":"2020-03-10","kind":"advisory","version":"3.22.0-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-13734","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-13734","date":"2026-10-08","epss":0.03948,"percentile":0.90138}],"risk":1.974,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-13734"},"relatedVulnerabilities":[{"id":"CVE-2019-13734","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-13734","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-13734","date":"2026-10-08","epss":0.03948,"percentile":0.90138}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00032.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00036.html","https://access.redhat.com/errata/RHSA-2019:4238","https://access.redhat.com/errata/RHSA-2020:0227","https://access.redhat.com/errata/RHSA-2020:0229","https://access.redhat.com/errata/RHSA-2020:0273","https://access.redhat.com/errata/RHSA-2020:0451","https://access.redhat.com/errata/RHSA-2020:0463","https://access.redhat.com/errata/RHSA-2020:0476","https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html","https://crbug.com/1025466","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2Z5M4FPUMDNX2LDPHJKN5ZV5GIS2AKNU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N5CIQCVS6E3ULJCNU7YJXJPO2BLQZDTK/","https://seclists.org/bugtraq/2020/Jan/27","https://security.gentoo.org/glsa/202003-08","https://usn.ubuntu.com/4298-1/","https://usn.ubuntu.com/4298-2/","https://www.debian.org/security/2020/dsa-4606","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-13734","description":"Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.8+10-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14583","versionConstraint":"< 11.0.8+10-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14583","fix":{"state":"fixed","versions":["11.0.8+10-0ubuntu1~18.04.1"],"available":[{"date":"2020-07-23","kind":"advisory","version":"11.0.8+10-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14583","date":"2026-10-08","epss":0.0392,"percentile":0.90064}],"risk":1.96,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14583"},"relatedVulnerabilities":[{"id":"CVE-2020-14583","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"impactScore":6.5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14583","date":"2026-10-08","epss":0.0392,"percentile":0.90064}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html","http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CFJPOYF3CWYEPCDOAOCNFJTQIKKWPHW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFZ36XIW5ENQAW6BB7WHRFFTTJX7KGMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/","https://security.gentoo.org/glsa/202008-24","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200717-0005/","https://usn.ubuntu.com/4433-1/","https://usn.ubuntu.com/4453-1/","https://www.debian.org/security/2020/dsa-4734","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14583","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-3446","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-3446","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-3446","date":"2026-10-08","epss":0.06531,"percentile":0.93621}],"risk":1.9593000000000003,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-3446"},"relatedVulnerabilities":[{"id":"CVE-2023-3446","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-3446","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-3446","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-3446","date":"2026-10-08","epss":0.06531,"percentile":0.93621}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1fa20cf2f506113c761777127a38bce5068740eb","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8780a896543a654e757db1b9396383f9d8095528","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9a0a4d3c1e7138915563c0df4fe6a3f9377b839c","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fc9867c1e03c22ebf56943be205202e576aabf23","https://www.openssl.org/news/secadv/20230719.txt","http://www.openwall.com/lists/oss-security/2023/07/19/4","http://www.openwall.com/lists/oss-security/2023/07/19/5","http://www.openwall.com/lists/oss-security/2023/07/19/6","http://www.openwall.com/lists/oss-security/2023/07/31/1","http://www.openwall.com/lists/oss-security/2024/05/16/1","https://lists.debian.org/debian-lts-announce/2023/08/msg00019.html","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230803-0011/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-3446","description":"Issue summary: Checking excessively long DH keys or parameters may be very slow.\n\nImpact summary: Applications that use the functions DH_check(), DH_check_ex()\nor EVP_PKEY_param_check() to check a DH key or DH parameters may experience long\ndelays. Where the key or parameters that are being checked have been obtained\nfrom an untrusted source this may lead to a Denial of Service.\n\nThe function DH_check() performs various checks on DH parameters. One of those\nchecks confirms that the modulus ('p' parameter) is not too large. Trying to use\na very large modulus is slow and OpenSSL will not normally use a modulus which\nis over 10,000 bits in length.\n\nHowever the DH_check() function checks numerous aspects of the key or parameters\nthat have been supplied. Some of those checks use the supplied modulus value\neven if it has already been found to be too large.\n\nAn application that calls DH_check() and supplies a key or parameters obtained\nfrom an untrusted source could be vulernable to a Denial of Service attack.\n\nThe function DH_check() is itself called by a number of other OpenSSL functions.\nAn application calling any of those other functions may similarly be affected.\nThe other functions affected by this are DH_check_ex() and\nEVP_PKEY_param_check().\n\nAlso vulnerable are the OpenSSL dhparam and pkeyparam command line applications\nwhen using the '-check' option.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\nThe OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-3446","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-3446","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-3446","date":"2026-10-08","epss":0.06531,"percentile":0.93621}],"risk":1.9593000000000003,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-3446"},"relatedVulnerabilities":[{"id":"CVE-2023-3446","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-3446","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-3446","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-3446","date":"2026-10-08","epss":0.06531,"percentile":0.93621}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1fa20cf2f506113c761777127a38bce5068740eb","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8780a896543a654e757db1b9396383f9d8095528","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9a0a4d3c1e7138915563c0df4fe6a3f9377b839c","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fc9867c1e03c22ebf56943be205202e576aabf23","https://www.openssl.org/news/secadv/20230719.txt","http://www.openwall.com/lists/oss-security/2023/07/19/4","http://www.openwall.com/lists/oss-security/2023/07/19/5","http://www.openwall.com/lists/oss-security/2023/07/19/6","http://www.openwall.com/lists/oss-security/2023/07/31/1","http://www.openwall.com/lists/oss-security/2024/05/16/1","https://lists.debian.org/debian-lts-announce/2023/08/msg00019.html","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230803-0011/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-3446","description":"Issue summary: Checking excessively long DH keys or parameters may be very slow.\n\nImpact summary: Applications that use the functions DH_check(), DH_check_ex()\nor EVP_PKEY_param_check() to check a DH key or DH parameters may experience long\ndelays. Where the key or parameters that are being checked have been obtained\nfrom an untrusted source this may lead to a Denial of Service.\n\nThe function DH_check() performs various checks on DH parameters. One of those\nchecks confirms that the modulus ('p' parameter) is not too large. Trying to use\na very large modulus is slow and OpenSSL will not normally use a modulus which\nis over 10,000 bits in length.\n\nHowever the DH_check() function checks numerous aspects of the key or parameters\nthat have been supplied. Some of those checks use the supplied modulus value\neven if it has already been found to be too large.\n\nAn application that calls DH_check() and supplies a key or parameters obtained\nfrom an untrusted source could be vulernable to a Denial of Service attack.\n\nThe function DH_check() is itself called by a number of other OpenSSL functions.\nAn application calling any of those other functions may similarly be affected.\nThe other functions affected by this are DH_check_ex() and\nEVP_PKEY_param_check().\n\nAlso vulnerable are the OpenSSL dhparam and pkeyparam command line applications\nwhen using the '-check' option.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\nThe OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue."}]},{"artifact":{"id":"8c95e64e888bf916","cpes":["cpe:2.3:a:com.squareup.retrofit2:retrofit:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:retrofit2:retrofit:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:retrofit:retrofit:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:squareup:retrofit:2.1.0:*:*:*:*:*:*:*"],"name":"retrofit","purl":"pkg:maven/com.squareup.retrofit2/retrofit@2.1.0","type":"java-archive","version":"2.1.0","language":"java","licenses":[],"metadata":{"pomGroupID":"com.squareup.retrofit2","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/retrofit-2.1.0.jar","manifestName":"","pomArtifactID":"retrofit","archiveDigests":[{"value":"2de7cd8b95b7021b1d597f049bcb422055119f2c","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/retrofit-2.1.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.5.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j379-9jr9-w5cq","versionConstraint":">=2.0.0,<2.5.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.squareup.retrofit2:retrofit","version":"2.1.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j379-9jr9-w5cq","fix":{"state":"fixed","versions":["2.5.0"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.5.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000844","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000844","date":"2026-10-08","epss":0.02152,"percentile":0.8159}],"risk":1.9475600000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-1000844","https://github.com/square/retrofit/pull/2735"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j379-9jr9-w5cq","description":"XML External Entity (XXE) vulnerability in Square Retrofit"},"relatedVulnerabilities":[{"id":"CVE-2018-1000844","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000844","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000844","date":"2026-10-08","epss":0.02152,"percentile":0.8159}],"urls":["https://github.com/square/retrofit/pull/2735"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000844","description":"Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerability in JAXB that can result in An attacker could use this to remotely read files from the file system or to perform SSRF.. This vulnerability appears to have been fixed in After commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wc4r-xq3c-5cf3","versionConstraint":">=8.5.0,<=8.5.100 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wc4r-xq3c-5cf3","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-49125","cwe":"CWE-288","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-49125","date":"2026-10-08","epss":0.03437,"percentile":0.88639}],"risk":1.9419049999999998,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-49125","https://lists.apache.org/thread/m66cytbfrty9k7dc4cg6tl1czhsnbywk","https://github.com/apache/tomcat/commit/7617b9c247bc77ed0444dd69adcd8aa48777886c","https://github.com/apache/tomcat/commit/9418e3ff9f1f4c006b4661311ae9376c52d162b9","https://github.com/apache/tomcat/commit/d94bd36fb7eb32e790dae0339bc249069649a637","https://tomcat.apache.org/security-10.html","https://tomcat.apache.org/security-11.html","https://tomcat.apache.org/security-9.html","http://www.openwall.com/lists/oss-security/2025/06/16/2","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wc4r-xq3c-5cf3","description":"Apache Tomcat - Security constraint bypass for pre/post-resources"},"relatedVulnerabilities":[{"id":"CVE-2025-49125","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-49125","cwe":"CWE-288","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-49125","date":"2026-10-08","epss":0.03437,"percentile":0.88639}],"urls":["https://lists.apache.org/thread/m66cytbfrty9k7dc4cg6tl1czhsnbywk","http://www.openwall.com/lists/oss-security/2025/06/16/2","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-49125","description":"Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions \nmay also be affected.\n\n\nUsers are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.8+10-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14593","versionConstraint":"< 11.0.8+10-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14593","fix":{"state":"fixed","versions":["11.0.8+10-0ubuntu1~18.04.1"],"available":[{"date":"2020-07-23","kind":"advisory","version":"11.0.8+10-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14593","date":"2026-10-08","epss":0.03846,"percentile":0.8986}],"risk":1.923,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14593"},"relatedVulnerabilities":[{"id":"CVE-2020-14593","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14593","date":"2026-10-08","epss":0.03846,"percentile":0.8986}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html","http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CFJPOYF3CWYEPCDOAOCNFJTQIKKWPHW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFZ36XIW5ENQAW6BB7WHRFFTTJX7KGMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/","https://security.gentoo.org/glsa/202008-24","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200717-0005/","https://usn.ubuntu.com/4433-1/","https://usn.ubuntu.com/4453-1/","https://www.debian.org/security/2020/dsa-4734","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14593","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N)."}]},{"artifact":{"id":"88bdd6da7cccc159","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-46143","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-46143","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-46143","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-46143","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-46143","date":"2026-10-08","epss":0.0379,"percentile":0.897}],"risk":1.8950000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-46143"},"relatedVulnerabilities":[{"id":"CVE-2021-46143","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-46143","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-46143","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-46143","date":"2026-10-08","epss":0.0379,"percentile":0.897}],"urls":["http://www.openwall.com/lists/oss-security/2022/01/17/3","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/issues/532","https://github.com/libexpat/libexpat/pull/538","https://security.gentoo.org/glsa/202209-24","https://security.netapp.com/advisory/ntap-20220121-0006/","https://www.debian.org/security/2022/dsa-5073","https://www.tenable.com/security/tns-2022-05"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-46143","description":"In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21283","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21283","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21283","cwe":"CWE-693","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21283","date":"2026-10-08","epss":0.03782,"percentile":0.89678}],"risk":1.891,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21283"},"relatedVulnerabilities":[{"id":"CVE-2022-21283","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21283","cwe":"CWE-693","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21283","date":"2026-10-08","epss":0.03782,"percentile":0.89678}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2DIN3L6L3SVZK75CKW2GPSU4HIGZR7XG/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21283","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21341","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21341","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21341","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21341","date":"2026-10-08","epss":0.03765,"percentile":0.89632}],"risk":1.8825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21341"},"relatedVulnerabilities":[{"id":"CVE-2022-21341","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21341","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21341","date":"2026-10-08","epss":0.03765,"percentile":0.89632}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21341","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21248","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21248","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2022-21248","date":"2026-10-08","epss":0.03763,"percentile":0.89624}],"risk":1.8815,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21248"},"relatedVulnerabilities":[{"id":"CVE-2022-21248","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-21248","date":"2026-10-08","epss":0.03763,"percentile":0.89624}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2DIN3L6L3SVZK75CKW2GPSU4HIGZR7XG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4J2N4FNXW6JKJBWUZH6SNI2UHCZXQXCY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPIWQ6DL5IPOT54UBWTISG5T24FQJ7MN/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21248","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.9+11-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14779","versionConstraint":"< 11.0.9+11-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14779","fix":{"state":"fixed","versions":["11.0.9+11-0ubuntu1~18.04.1"],"available":[{"date":"2020-10-27","kind":"advisory","version":"11.0.9+11-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14779","date":"2026-10-08","epss":0.03758,"percentile":0.89608}],"risk":1.879,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14779"},"relatedVulnerabilities":[{"id":"CVE-2020-14779","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14779","date":"2026-10-08","epss":0.03758,"percentile":0.89608}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://lists.debian.org/debian-lts-announce/2020/10/msg00031.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6CJCO52DHIQJHLPF6HMTC5Z2VKFRQMY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OMJMTXFJRONFT72YAEQNRFKYZZU4W3HD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XKRGVMZT3EUUWKUA6DBT56FT3UOKPHQ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVPLGNHNJ4UJ6IO6R2XXEKCTCI2DRPDQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YCKZAI4AWSKO5O5VDXHFFKNLOZGZ3KEE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7XEONOP6JB7SD7AMUWZTLZF2L4QD546/","https://security.gentoo.org/glsa/202101-19","https://security.netapp.com/advisory/ntap-20201023-0004/","https://www.debian.org/security/2020/dsa-4779","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14779","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.5+10-0ubuntu1.1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2981","versionConstraint":"< 11.0.5+10-0ubuntu1.1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2981","fix":{"state":"fixed","versions":["11.0.5+10-0ubuntu1.1~18.04"],"available":[{"date":"2019-12-17","kind":"advisory","version":"11.0.5+10-0ubuntu1.1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2981","date":"2026-10-08","epss":0.03732,"percentile":0.89542}],"risk":1.8659999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2981"},"relatedVulnerabilities":[{"id":"CVE-2019-2981","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2981","date":"2026-10-08","epss":0.03732,"percentile":0.89542}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://access.redhat.com/errata/RHSA-2019:3134","https://access.redhat.com/errata/RHSA-2019:3135","https://access.redhat.com/errata/RHSA-2019:3136","https://access.redhat.com/errata/RHSA-2019:3157","https://access.redhat.com/errata/RHSA-2019:3158","https://access.redhat.com/errata/RHSA-2019:4109","https://access.redhat.com/errata/RHSA-2019:4110","https://access.redhat.com/errata/RHSA-2019:4113","https://access.redhat.com/errata/RHSA-2019:4115","https://access.redhat.com/errata/RHSA-2020:0006","https://access.redhat.com/errata/RHSA-2020:0046","https://lists.debian.org/debian-lts-announce/2019/12/msg00005.html","https://seclists.org/bugtraq/2019/Oct/27","https://seclists.org/bugtraq/2019/Oct/31","https://security.netapp.com/advisory/ntap-20191017-0001/","https://usn.ubuntu.com/4223-1/","https://www.debian.org/security/2019/dsa-4546","https://www.debian.org/security/2019/dsa-4548"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2981","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.5+10-0ubuntu1.1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2983","versionConstraint":"< 11.0.5+10-0ubuntu1.1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2983","fix":{"state":"fixed","versions":["11.0.5+10-0ubuntu1.1~18.04"],"available":[{"date":"2019-12-17","kind":"advisory","version":"11.0.5+10-0ubuntu1.1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2983","date":"2026-10-08","epss":0.03732,"percentile":0.89542}],"risk":1.8659999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2983"},"relatedVulnerabilities":[{"id":"CVE-2019-2983","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2983","date":"2026-10-08","epss":0.03732,"percentile":0.89542}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://access.redhat.com/errata/RHSA-2019:3134","https://access.redhat.com/errata/RHSA-2019:3135","https://access.redhat.com/errata/RHSA-2019:3136","https://access.redhat.com/errata/RHSA-2019:3157","https://access.redhat.com/errata/RHSA-2019:3158","https://access.redhat.com/errata/RHSA-2019:4109","https://access.redhat.com/errata/RHSA-2019:4110","https://access.redhat.com/errata/RHSA-2019:4113","https://access.redhat.com/errata/RHSA-2019:4115","https://access.redhat.com/errata/RHSA-2020:0006","https://access.redhat.com/errata/RHSA-2020:0046","https://lists.debian.org/debian-lts-announce/2019/12/msg00005.html","https://seclists.org/bugtraq/2019/Oct/27","https://seclists.org/bugtraq/2019/Oct/31","https://security.netapp.com/advisory/ntap-20191017-0001/","https://usn.ubuntu.com/4223-1/","https://www.debian.org/security/2019/dsa-4546","https://www.debian.org/security/2019/dsa-4548"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2983","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.5+10-0ubuntu1.1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2973","versionConstraint":"< 11.0.5+10-0ubuntu1.1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2973","fix":{"state":"fixed","versions":["11.0.5+10-0ubuntu1.1~18.04"],"available":[{"date":"2019-12-17","kind":"advisory","version":"11.0.5+10-0ubuntu1.1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2973","date":"2026-10-08","epss":0.03715,"percentile":0.89482}],"risk":1.8575000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2973"},"relatedVulnerabilities":[{"id":"CVE-2019-2973","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2973","date":"2026-10-08","epss":0.03715,"percentile":0.89482}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://access.redhat.com/errata/RHSA-2019:3134","https://access.redhat.com/errata/RHSA-2019:3135","https://access.redhat.com/errata/RHSA-2019:3136","https://access.redhat.com/errata/RHSA-2019:3157","https://access.redhat.com/errata/RHSA-2019:3158","https://access.redhat.com/errata/RHSA-2019:4109","https://access.redhat.com/errata/RHSA-2019:4110","https://access.redhat.com/errata/RHSA-2019:4113","https://access.redhat.com/errata/RHSA-2019:4115","https://access.redhat.com/errata/RHSA-2020:0006","https://access.redhat.com/errata/RHSA-2020:0046","https://lists.debian.org/debian-lts-announce/2019/12/msg00005.html","https://seclists.org/bugtraq/2019/Oct/27","https://seclists.org/bugtraq/2019/Oct/31","https://security.netapp.com/advisory/ntap-20191017-0001/","https://usn.ubuntu.com/4223-1/","https://www.debian.org/security/2019/dsa-4546","https://www.debian.org/security/2019/dsa-4548"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2973","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1549","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-1549","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.6"],"available":[{"date":"2020-05-28","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-1549","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1549","date":"2026-10-08","epss":0.06182,"percentile":0.93317}],"risk":1.8546,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1549"},"relatedVulnerabilities":[{"id":"CVE-2019-1549","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1549","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1549","date":"2026-10-08","epss":0.06182,"percentile":0.93317}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=1b0fe00e2704b5e20334a16d3c9099d1ba2ef1be","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GY6SNRJP2S7Y42GIIDO3HXPNMDYN2U3A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZN4VVQJ3JDCHGIHV4Y2YTXBYQZ6PWQ7E/","https://seclists.org/bugtraq/2019/Oct/1","https://security.netapp.com/advisory/ntap-20190919-0002/","https://support.f5.com/csp/article/K44070243","https://support.f5.com/csp/article/K44070243?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4376-1/","https://www.debian.org/security/2019/dsa-4539","https://www.openssl.org/news/secadv/20190910.txt","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1549","description":"OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. However this protection was not being used in the default case. A partial mitigation for this issue is that the output from a high precision timer is mixed into the RNG state so the likelihood of a parent and child process sharing state is significantly reduced. If an application already calls OPENSSL_init_crypto() explicitly using OPENSSL_INIT_ATFORK then this problem does not occur at all. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c)."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-1549","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-1549","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.6"],"available":[{"date":"2020-05-28","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-1549","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1549","date":"2026-10-08","epss":0.06182,"percentile":0.93317}],"risk":1.8546,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1549"},"relatedVulnerabilities":[{"id":"CVE-2019-1549","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1549","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1549","date":"2026-10-08","epss":0.06182,"percentile":0.93317}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=1b0fe00e2704b5e20334a16d3c9099d1ba2ef1be","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GY6SNRJP2S7Y42GIIDO3HXPNMDYN2U3A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZN4VVQJ3JDCHGIHV4Y2YTXBYQZ6PWQ7E/","https://seclists.org/bugtraq/2019/Oct/1","https://security.netapp.com/advisory/ntap-20190919-0002/","https://support.f5.com/csp/article/K44070243","https://support.f5.com/csp/article/K44070243?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4376-1/","https://www.debian.org/security/2019/dsa-4539","https://www.openssl.org/news/secadv/20190910.txt","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1549","description":"OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. However this protection was not being used in the default case. A partial mitigation for this issue is that the output from a high precision timer is mixed into the RNG state so the likelihood of a parent and child process sharing state is significantly reduced. If an application already calls OPENSSL_init_crypto() explicitly using OPENSSL_INIT_ATFORK then this problem does not occur at all. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c)."}]},{"artifact":{"id":"3571b4891e14d0b5","cpes":["cpe:2.3:a:libidn2-0:libidn2-0:2.0.4-1.1build2:*:*:*:*:*:*:*","cpe:2.3:a:libidn2-0:libidn2_0:2.0.4-1.1build2:*:*:*:*:*:*:*","cpe:2.3:a:libidn2_0:libidn2-0:2.0.4-1.1build2:*:*:*:*:*:*:*","cpe:2.3:a:libidn2_0:libidn2_0:2.0.4-1.1build2:*:*:*:*:*:*:*","cpe:2.3:a:libidn2:libidn2-0:2.0.4-1.1build2:*:*:*:*:*:*:*","cpe:2.3:a:libidn2:libidn2_0:2.0.4-1.1build2:*:*:*:*:*:*:*"],"name":"libidn2-0","purl":"pkg:deb/ubuntu/libidn2-0@2.0.4-1.1build2?arch=amd64&distro=ubuntu-18.04&upstream=libidn2","type":"deb","version":"2.0.4-1.1build2","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-3","LGPL-3+","Unicode"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libidn2-0/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libidn2-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libidn2-0:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libidn2-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libidn2"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.0.4-1.1ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-18224","versionConstraint":"< 2.0.4-1.1ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"libidn2","version":"2.0.4-1.1build2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-18224","fix":{"state":"fixed","versions":["2.0.4-1.1ubuntu0.2"],"available":[{"date":"2019-10-29","kind":"advisory","version":"2.0.4-1.1ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-18224","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-18224","date":"2026-10-08","epss":0.03708,"percentile":0.89459}],"risk":1.854,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-18224"},"relatedVulnerabilities":[{"id":"CVE-2019-18224","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-18224","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-18224","date":"2026-10-08","epss":0.03708,"percentile":0.89459}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00008.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00009.html","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12420","https://github.com/libidn/libidn2/commit/e4d1558aa2c1c04a05066ee8600f37603890ba8c","https://github.com/libidn/libidn2/compare/libidn2-2.1.0...libidn2-2.1.1","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JDQVQ2XPV5BTZUFINT7AFJSKNNBVURNJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MINU5RKDFE6TKAFY5DRFN3WSFDS4DYVS/","https://seclists.org/bugtraq/2020/Feb/4","https://security.gentoo.org/glsa/202003-63","https://usn.ubuntu.com/4168-1/","https://www.debian.org/security/2020/dsa-4613"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-18224","description":"idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string."}]},{"artifact":{"id":"c67e239bf70af34c","cpes":["cpe:2.3:a:libasn1-8-heimdal:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1-8-heimdal:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8_heimdal:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8_heimdal:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1-8:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1-8:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libasn1-8-heimdal","purl":"pkg:deb/ubuntu/libasn1-8-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libasn1-8-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libasn1-8-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libasn1-8-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libasn1-8-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"489fa43422e60874","cpes":["cpe:2.3:a:libgssapi3-heimdal:libgssapi3-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3-heimdal:libgssapi3_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3_heimdal:libgssapi3-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3_heimdal:libgssapi3_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3:libgssapi3-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3:libgssapi3_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libgssapi3-heimdal","purl":"pkg:deb/ubuntu/libgssapi3-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi3-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libgssapi3-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi3-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libgssapi3-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"8af38808136cd0ba","cpes":["cpe:2.3:a:libhcrypto4-heimdal:libhcrypto4-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4-heimdal:libhcrypto4_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4_heimdal:libhcrypto4-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4_heimdal:libhcrypto4_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4:libhcrypto4-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4:libhcrypto4_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libhcrypto4-heimdal","purl":"pkg:deb/ubuntu/libhcrypto4-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libhcrypto4-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libhcrypto4-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libhcrypto4-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libhcrypto4-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"4fe49c3e8d200f83","cpes":["cpe:2.3:a:libheimbase1-heimdal:libheimbase1-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1-heimdal:libheimbase1_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1_heimdal:libheimbase1-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1_heimdal:libheimbase1_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1:libheimbase1-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1:libheimbase1_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libheimbase1-heimdal","purl":"pkg:deb/ubuntu/libheimbase1-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheimbase1-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libheimbase1-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheimbase1-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libheimbase1-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"5ac1d9d8c3d94a69","cpes":["cpe:2.3:a:libheimntlm0-heimdal:libheimntlm0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0-heimdal:libheimntlm0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0_heimdal:libheimntlm0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0_heimdal:libheimntlm0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0:libheimntlm0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0:libheimntlm0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libheimntlm0-heimdal","purl":"pkg:deb/ubuntu/libheimntlm0-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheimntlm0-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libheimntlm0-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheimntlm0-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libheimntlm0-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"5aedfa9521e17f6a","cpes":["cpe:2.3:a:libhx509-5-heimdal:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509-5-heimdal:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5_heimdal:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5_heimdal:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509-5:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509-5:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libhx509-5-heimdal","purl":"pkg:deb/ubuntu/libhx509-5-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libhx509-5-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libhx509-5-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libhx509-5-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libhx509-5-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"ec3f5f14c892446a","cpes":["cpe:2.3:a:libkrb5-26-heimdal:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-26-heimdal:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26_heimdal:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26_heimdal:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-26:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-26:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libkrb5-26-heimdal","purl":"pkg:deb/ubuntu/libkrb5-26-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-26-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libkrb5-26-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-26-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libkrb5-26-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"d29c0be392861a2d","cpes":["cpe:2.3:a:libroken18-heimdal:libroken18-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18-heimdal:libroken18_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18_heimdal:libroken18-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18_heimdal:libroken18_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18:libroken18-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18:libroken18_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libroken18-heimdal","purl":"pkg:deb/ubuntu/libroken18-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libroken18-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libroken18-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libroken18-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libroken18-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"4c95d1ed3ad0ede5","cpes":["cpe:2.3:a:libwind0-heimdal:libwind0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0-heimdal:libwind0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0_heimdal:libwind0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0_heimdal:libwind0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0:libwind0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0:libwind0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libwind0-heimdal","purl":"pkg:deb/ubuntu/libwind0-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwind0-heimdal/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libwind0-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwind0-heimdal:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libwind0-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"0b1c74783f88c915","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.22.0-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-9327","versionConstraint":"< 3.22.0-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-9327","fix":{"state":"fixed","versions":["3.22.0-1ubuntu0.3"],"available":[{"date":"2020-03-10","kind":"advisory","version":"3.22.0-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-9327","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-9327","date":"2026-10-08","epss":0.03683,"percentile":0.89388}],"risk":1.8415000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-9327"},"relatedVulnerabilities":[{"id":"CVE-2020-9327","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9327","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-9327","date":"2026-10-08","epss":0.03683,"percentile":0.89388}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://security.gentoo.org/glsa/202003-16","https://security.netapp.com/advisory/ntap-20200313-0002/","https://usn.ubuntu.com/4298-1/","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.sqlite.org/cgi/src/info/4374860b29383380","https://www.sqlite.org/cgi/src/info/9d0d4ab95dc0c56e","https://www.sqlite.org/cgi/src/info/abc473fb8fb99900"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-9327","description":"In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20852","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-20852","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-20852","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-20852","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-20852","date":"2026-10-08","epss":0.03668,"percentile":0.89348}],"risk":1.8339999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-20852"},"relatedVulnerabilities":[{"id":"CVE-2018-20852","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20852","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-20852","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-20852","date":"2026-10-08","epss":0.03668,"percentile":0.89348}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00071.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00074.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","https://access.redhat.com/errata/RHSA-2019:3725","https://access.redhat.com/errata/RHSA-2019:3948","https://bugs.python.org/issue35121","https://lists.debian.org/debian-lts-announce/2019/08/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/08/msg00040.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/COATURTCY7G67AYI6UDV5B2JZTBCKIDX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K7HNVIFMETMFWWWUNTB72KYJYXCZOS5V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBTGPBUABGXZ7WH7677OEM3NSP6ZEA76/","https://python-security.readthedocs.io/vuln/cookie-domain-check.html","https://security.gentoo.org/glsa/202003-26","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/","https://www.oracle.com/security-alerts/cpuapr2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20852","description":"http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by using a server with a hostname that has another valid hostname as a suffix (e.g., pythonicexample.com to steal cookies for example.com). When a program uses http.cookiejar.DefaultPolicy and tries to do an HTTP connection to an attacker-controlled server, existing cookies can be leaked to the attacker. This affects 2.x through 2.7.16, 3.x before 3.4.10, 3.5.x before 3.5.7, 3.6.x before 3.6.9, and 3.7.x before 3.7.3."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20852","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-20852","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-20852","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-20852","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-20852","date":"2026-10-08","epss":0.03668,"percentile":0.89348}],"risk":1.8339999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-20852"},"relatedVulnerabilities":[{"id":"CVE-2018-20852","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20852","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-20852","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-20852","date":"2026-10-08","epss":0.03668,"percentile":0.89348}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00071.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00074.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","https://access.redhat.com/errata/RHSA-2019:3725","https://access.redhat.com/errata/RHSA-2019:3948","https://bugs.python.org/issue35121","https://lists.debian.org/debian-lts-announce/2019/08/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/08/msg00040.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/COATURTCY7G67AYI6UDV5B2JZTBCKIDX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K7HNVIFMETMFWWWUNTB72KYJYXCZOS5V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBTGPBUABGXZ7WH7677OEM3NSP6ZEA76/","https://python-security.readthedocs.io/vuln/cookie-domain-check.html","https://security.gentoo.org/glsa/202003-26","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/","https://www.oracle.com/security-alerts/cpuapr2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20852","description":"http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by using a server with a hostname that has another valid hostname as a suffix (e.g., pythonicexample.com to steal cookies for example.com). When a program uses http.cookiejar.DefaultPolicy and tries to do an HTTP connection to an attacker-controlled server, existing cookies can be leaked to the attacker. This affects 2.x through 2.7.16, 3.x before 3.4.10, 3.5.x before 3.5.7, 3.6.x before 3.6.9, and 3.7.x before 3.7.3."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-20852","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-20852","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-20852","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-20852","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-20852","date":"2026-10-08","epss":0.03668,"percentile":0.89348}],"risk":1.8339999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-20852"},"relatedVulnerabilities":[{"id":"CVE-2018-20852","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20852","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-20852","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-20852","date":"2026-10-08","epss":0.03668,"percentile":0.89348}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00071.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00074.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","https://access.redhat.com/errata/RHSA-2019:3725","https://access.redhat.com/errata/RHSA-2019:3948","https://bugs.python.org/issue35121","https://lists.debian.org/debian-lts-announce/2019/08/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/08/msg00040.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/COATURTCY7G67AYI6UDV5B2JZTBCKIDX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K7HNVIFMETMFWWWUNTB72KYJYXCZOS5V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBTGPBUABGXZ7WH7677OEM3NSP6ZEA76/","https://python-security.readthedocs.io/vuln/cookie-domain-check.html","https://security.gentoo.org/glsa/202003-26","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/","https://www.oracle.com/security-alerts/cpuapr2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20852","description":"http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by using a server with a hostname that has another valid hostname as a suffix (e.g., pythonicexample.com to steal cookies for example.com). When a program uses http.cookiejar.DefaultPolicy and tries to do an HTTP connection to an attacker-controlled server, existing cookies can be leaked to the attacker. This affects 2.x through 2.7.16, 3.x before 3.4.10, 3.5.x before 3.5.7, 3.6.x before 3.6.9, and 3.7.x before 3.7.3."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.15-4ubuntu4~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20852","versionConstraint":"< 2.7.15-4ubuntu4~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-20852","fix":{"state":"fixed","versions":["2.7.15-4ubuntu4~18.04.1"],"available":[{"date":"2019-09-09","kind":"advisory","version":"2.7.15-4ubuntu4~18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-20852","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-20852","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-20852","date":"2026-10-08","epss":0.03668,"percentile":0.89348}],"risk":1.8339999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-20852"},"relatedVulnerabilities":[{"id":"CVE-2018-20852","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20852","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-20852","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-20852","date":"2026-10-08","epss":0.03668,"percentile":0.89348}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00071.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00074.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","https://access.redhat.com/errata/RHSA-2019:3725","https://access.redhat.com/errata/RHSA-2019:3948","https://bugs.python.org/issue35121","https://lists.debian.org/debian-lts-announce/2019/08/msg00022.html","https://lists.debian.org/debian-lts-announce/2019/08/msg00040.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/COATURTCY7G67AYI6UDV5B2JZTBCKIDX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K7HNVIFMETMFWWWUNTB72KYJYXCZOS5V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBTGPBUABGXZ7WH7677OEM3NSP6ZEA76/","https://python-security.readthedocs.io/vuln/cookie-domain-check.html","https://security.gentoo.org/glsa/202003-26","https://usn.ubuntu.com/4127-1/","https://usn.ubuntu.com/4127-2/","https://www.oracle.com/security-alerts/cpuapr2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20852","description":"http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by using a server with a hostname that has another valid hostname as a suffix (e.g., pythonicexample.com to steal cookies for example.com). When a program uses http.cookiejar.DefaultPolicy and tries to do an HTTP connection to an attacker-controlled server, existing cookies can be leaked to the attacker. This affects 2.x through 2.7.16, 3.x before 3.4.10, 3.5.x before 3.5.7, 3.6.x before 3.6.9, and 3.7.x before 3.7.3."}]},{"artifact":{"id":"e5cacd3d2ad9d076","cpes":["cpe:2.3:a:libgnutls30:libgnutls30:3.5.18-1ubuntu1:*:*:*:*:*:*:*"],"name":"libgnutls30","purl":"pkg:deb/ubuntu/libgnutls30@3.5.18-1ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=gnutls28","type":"deb","version":"3.5.18-1ubuntu1","language":"","licenses":["sha256:d3c67562f8ada637da00685c1142be4345ca259373fe01092239fb678d1a7afd"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libgnutls30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libgnutls30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.18-1ubuntu1.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-10844","versionConstraint":"< 3.5.18-1ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"gnutls28","version":"3.5.18-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-10844","fix":{"state":"fixed","versions":["3.5.18-1ubuntu1.1"],"available":[{"date":"2019-05-30","kind":"advisory","version":"3.5.18-1ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-10844","cwe":"CWE-385","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-10844","cwe":"CWE-327","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-10844","date":"2026-10-08","epss":0.03623,"percentile":0.89215}],"risk":1.8114999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-10844"},"relatedVulnerabilities":[{"id":"CVE-2018-10844","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-10844","cwe":"CWE-385","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-10844","cwe":"CWE-327","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-10844","date":"2026-10-08","epss":0.03623,"percentile":0.89215}],"urls":["http://www.securityfocus.com/bid/105138","https://access.redhat.com/errata/RHSA-2018:3050","https://access.redhat.com/errata/RHSA-2018:3505","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10844","https://eprint.iacr.org/2018/747","https://gitlab.com/gnutls/gnutls/merge_requests/657","https://lists.debian.org/debian-lts-announce/2018/10/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ILMOWPKMTZAIMK5F32TUMO34XCABUCFJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDYY3R4F5CUTFAMXH2C5NKYFVDEJLTT7/","https://usn.ubuntu.com/3999-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10844","description":"It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data using crafted packets."}]},{"artifact":{"id":"e5cacd3d2ad9d076","cpes":["cpe:2.3:a:libgnutls30:libgnutls30:3.5.18-1ubuntu1:*:*:*:*:*:*:*"],"name":"libgnutls30","purl":"pkg:deb/ubuntu/libgnutls30@3.5.18-1ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=gnutls28","type":"deb","version":"3.5.18-1ubuntu1","language":"","licenses":["sha256:d3c67562f8ada637da00685c1142be4345ca259373fe01092239fb678d1a7afd"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libgnutls30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libgnutls30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.18-1ubuntu1.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-10845","versionConstraint":"< 3.5.18-1ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"gnutls28","version":"3.5.18-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-10845","fix":{"state":"fixed","versions":["3.5.18-1ubuntu1.1"],"available":[{"date":"2019-05-30","kind":"advisory","version":"3.5.18-1ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-10845","cwe":"CWE-385","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-10845","cwe":"CWE-327","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-10845","date":"2026-10-08","epss":0.03623,"percentile":0.89215}],"risk":1.8114999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-10845"},"relatedVulnerabilities":[{"id":"CVE-2018-10845","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-10845","cwe":"CWE-385","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-10845","cwe":"CWE-327","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-10845","date":"2026-10-08","epss":0.03623,"percentile":0.89215}],"urls":["http://www.securityfocus.com/bid/105138","https://access.redhat.com/errata/RHSA-2018:3050","https://access.redhat.com/errata/RHSA-2018:3505","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10845","https://eprint.iacr.org/2018/747","https://gitlab.com/gnutls/gnutls/merge_requests/657","https://lists.debian.org/debian-lts-announce/2018/10/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ILMOWPKMTZAIMK5F32TUMO34XCABUCFJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDYY3R4F5CUTFAMXH2C5NKYFVDEJLTT7/","https://usn.ubuntu.com/3999-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10845","description":"It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.6+10-1ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-2655","versionConstraint":"< 11.0.6+10-1ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-2655","fix":{"state":"fixed","versions":["11.0.6+10-1ubuntu1~18.04.1"],"available":[{"date":"2020-01-28","kind":"advisory","version":"11.0.6+10-1ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-2655","date":"2026-10-08","epss":0.03613,"percentile":0.89187}],"risk":1.8065000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-2655"},"relatedVulnerabilities":[{"id":"CVE-2020-2655","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-2655","date":"2026-10-08","epss":0.03613,"percentile":0.89187}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00050.html","https://access.redhat.com/errata/RHSA-2020:0122","https://access.redhat.com/errata/RHSA-2020:0128","https://access.redhat.com/errata/RHSA-2020:0232","https://seclists.org/bugtraq/2020/Jan/24","https://security.netapp.com/advisory/ntap-20200122-0003/","https://usn.ubuntu.com/4257-1/","https://www.debian.org/security/2020/dsa-4605","https://www.oracle.com/security-alerts/cpujan2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-2655","description":"Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.5 and 13.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data as well as unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)."}]},{"artifact":{"id":"0b1c74783f88c915","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.22.0-1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9937","versionConstraint":"< 3.22.0-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9937","fix":{"state":"fixed","versions":["3.22.0-1ubuntu0.1"],"available":[{"date":"2019-06-19","kind":"advisory","version":"3.22.0-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9937","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9937","date":"2026-10-08","epss":0.06011,"percentile":0.93154}],"risk":1.8032999999999997,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9937"},"relatedVulnerabilities":[{"id":"CVE-2019-9937","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9937","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9937","date":"2026-10-08","epss":0.06011,"percentile":0.93154}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00026.html","http://www.securityfocus.com/bid/107562","https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXD2GYJVTDGEQPUNMMMC5TB7MQXOBBMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N66U5PY5UJU4XBFZJH7QNKIDNAVIB4OP/","https://security.gentoo.org/glsa/201908-09","https://security.netapp.com/advisory/ntap-20190416-0005/","https://sqlite.org/src/info/45c73deb440496e8","https://usn.ubuntu.com/4019-1/","https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114383.html","https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114393.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9937","description":"In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.5+10-0ubuntu1.1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2949","versionConstraint":"< 11.0.5+10-0ubuntu1.1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2949","fix":{"state":"fixed","versions":["11.0.5+10-0ubuntu1.1~18.04"],"available":[{"date":"2019-12-17","kind":"advisory","version":"11.0.5+10-0ubuntu1.1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2949","date":"2026-10-08","epss":0.03586,"percentile":0.89111}],"risk":1.7930000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2949"},"relatedVulnerabilities":[{"id":"CVE-2019-2949","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2949","date":"2026-10-08","epss":0.03586,"percentile":0.89111}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://access.redhat.com/errata/RHSA-2019:3134","https://access.redhat.com/errata/RHSA-2019:3135","https://access.redhat.com/errata/RHSA-2019:3136","https://kc.mcafee.com/corporate/index?page=content&id=SB10315","https://lists.debian.org/debian-lts-announce/2019/12/msg00005.html","https://seclists.org/bugtraq/2019/Oct/27","https://seclists.org/bugtraq/2019/Oct/31","https://security.netapp.com/advisory/ntap-20191017-0001/","https://support.f5.com/csp/article/K54213762?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4223-1/","https://www.debian.org/security/2019/dsa-4546","https://www.debian.org/security/2019/dsa-4548"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2949","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N)."}]},{"artifact":{"id":"91ad4ea54a8353ff","cpes":["cpe:2.3:a:perl-base:perl-base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.26.1-6ubuntu0.3?arch=amd64&distro=ubuntu-18.04&upstream=perl","type":"deb","version":"5.26.1-6ubuntu0.3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.26.1-6ubuntu0.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-12723","versionConstraint":"< 5.26.1-6ubuntu0.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"perl","version":"5.26.1-6ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-12723","fix":{"state":"fixed","versions":["5.26.1-6ubuntu0.5"],"available":[{"date":"2020-10-26","kind":"advisory","version":"5.26.1-6ubuntu0.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-12723","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-12723","date":"2026-10-08","epss":0.05971,"percentile":0.93112}],"risk":1.7913,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-12723"},"relatedVulnerabilities":[{"id":"CVE-2020-12723","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-12723","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-12723","date":"2026-10-08","epss":0.05971,"percentile":0.93112}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.html","https://github.com/Perl/perl5/blob/blead/pod/perl5303delta.pod","https://github.com/Perl/perl5/compare/v5.30.2...v5.30.3","https://github.com/Perl/perl5/issues/16947","https://github.com/Perl/perl5/issues/17743","https://github.com/perl/perl5/commit/66bbb51b93253a3f87d11c2695cfb7bdb782184a","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE/","https://security.gentoo.org/glsa/202006-03","https://security.netapp.com/advisory/ntap-20200611-0001/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-12723","description":"regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-38546","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-38546","fix":{"state":"wont-fix","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2023-38546","date":"2026-10-08","epss":0.05956,"percentile":0.931}],"risk":1.7868,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-38546"},"relatedVulnerabilities":[{"id":"CVE-2023-38546","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-38546","date":"2026-10-08","epss":0.05956,"percentile":0.931}],"urls":["http://seclists.org/fulldisclosure/2024/Jan/34","http://seclists.org/fulldisclosure/2024/Jan/37","http://seclists.org/fulldisclosure/2024/Jan/38","https://curl.se/docs/CVE-2023-38546.html","https://forum.vmssoftware.com/viewtopic.php?f=8&t=8868","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OGMXNRNSJ4ETDK6FRNU3J7SABXPWCHSQ/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214057","https://support.apple.com/kb/HT214058","https://support.apple.com/kb/HT214063","https://lists.debian.org/debian-lts-announce/2023/10/msg00016.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-093430.html","https://cert-portal.siemens.com/productcert/html/ssa-832273.html","https://cert-portal.siemens.com/productcert/html/ssa-943925.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-38546","description":"This flaw allows an attacker to insert cookies at will into a running program\nusing libcurl, if the specific series of conditions are met.\n\nlibcurl performs transfers. In its API, an application creates \"easy handles\"\nthat are the individual handles for single transfers.\n\nlibcurl provides a function call that duplicates en easy handle called\n[curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html).\n\nIf a transfer has cookies enabled when the handle is duplicated, the\ncookie-enable state is also cloned - but without cloning the actual\ncookies. If the source handle did not read any cookies from a specific file on\ndisk, the cloned version of the handle would instead store the file name as\n`none` (using the four ASCII letters, no quotes).\n\nSubsequent use of the cloned handle that does not explicitly set a source to\nload cookies from would then inadvertently load cookies from a file named\n`none` - if such a file exists and is readable in the current directory of the\nprogram using libcurl. And if using the correct file format of course."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-38546","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-38546","fix":{"state":"wont-fix","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2023-38546","date":"2026-10-08","epss":0.05956,"percentile":0.931}],"risk":1.7868,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-38546"},"relatedVulnerabilities":[{"id":"CVE-2023-38546","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-38546","date":"2026-10-08","epss":0.05956,"percentile":0.931}],"urls":["http://seclists.org/fulldisclosure/2024/Jan/34","http://seclists.org/fulldisclosure/2024/Jan/37","http://seclists.org/fulldisclosure/2024/Jan/38","https://curl.se/docs/CVE-2023-38546.html","https://forum.vmssoftware.com/viewtopic.php?f=8&t=8868","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OGMXNRNSJ4ETDK6FRNU3J7SABXPWCHSQ/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214057","https://support.apple.com/kb/HT214058","https://support.apple.com/kb/HT214063","https://lists.debian.org/debian-lts-announce/2023/10/msg00016.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-093430.html","https://cert-portal.siemens.com/productcert/html/ssa-832273.html","https://cert-portal.siemens.com/productcert/html/ssa-943925.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-38546","description":"This flaw allows an attacker to insert cookies at will into a running program\nusing libcurl, if the specific series of conditions are met.\n\nlibcurl performs transfers. In its API, an application creates \"easy handles\"\nthat are the individual handles for single transfers.\n\nlibcurl provides a function call that duplicates en easy handle called\n[curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html).\n\nIf a transfer has cookies enabled when the handle is duplicated, the\ncookie-enable state is also cloned - but without cloning the actual\ncookies. If the source handle did not read any cookies from a specific file on\ndisk, the cloned version of the handle would instead store the file name as\n`none` (using the four ASCII letters, no quotes).\n\nSubsequent use of the cloned handle that does not explicitly set a source to\nload cookies from would then inadvertently load cookies from a file named\n`none` - if such a file exists and is readable in the current directory of the\nprogram using libcurl. And if using the correct file format of course."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.11+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-2163","versionConstraint":"< 11.0.11+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-2163","fix":{"state":"fixed","versions":["11.0.11+9-0ubuntu2~18.04"],"available":[{"date":"2021-04-27","kind":"advisory","version":"11.0.11+9-0ubuntu2~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-2163","date":"2026-10-08","epss":0.03566,"percentile":0.89036}],"risk":1.783,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-2163"},"relatedVulnerabilities":[{"id":"CVE-2021-2163","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-2163","date":"2026-10-08","epss":0.03566,"percentile":0.89036}],"urls":["https://lists.debian.org/debian-lts-announce/2021/04/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5ACX4JEVYH6H4PSMGMYWTGABPOFPH3TS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CFXOKM2233JVGYDOWW77BN54X3GZTIBK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CG7EWXSO6JUCVHP7R3SOZQ7WPNBOISJH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MAULPCQFLAMBJIS27YLNNX6IHRFJMVP4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MVDY4T5XMSYDQT6RRKPMRCV4MVGS7KXF/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UD3JEP4HPLK7MNZHVUMKIJPBP74M3A2V/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20210513-0001/","https://www.debian.org/security/2021/dsa-4899","https://www.oracle.com/security-alerts/cpuapr2021.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-2163","description":"Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM Enterprise Edition: 19.3.5, 20.3.1.2 and 21.0.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N)."}]},{"artifact":{"id":"a5ac54476e47c1ea","cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.35-2ubuntu2.1:*:*:*:*:*:*:*"],"name":"libnss3","purl":"pkg:deb/ubuntu/libnss3@2%3A3.35-2ubuntu2.1?arch=amd64&distro=ubuntu-18.04&upstream=nss","type":"deb","version":"2:3.35-2ubuntu2.1","language":"","licenses":["HPND","HPND-sell-variant","MIT","MPL-2.0","Zlib","blessing"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss3/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libnss3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nss"}]},"matchDetails":[{"fix":{"suggestedVersion":"2:3.35-2ubuntu2.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-17006","versionConstraint":"< 2:3.35-2ubuntu2.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nss","version":"2:3.35-2ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-17006","fix":{"state":"fixed","versions":["2:3.35-2ubuntu2.7"],"available":[{"date":"2020-01-08","kind":"advisory","version":"2:3.35-2ubuntu2.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-17006","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-17006","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-17006","date":"2026-10-08","epss":0.03558,"percentile":0.89009}],"risk":1.779,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-17006"},"relatedVulnerabilities":[{"id":"CVE-2019-17006","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-17006","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-17006","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-17006","date":"2026-10-08","epss":0.03558,"percentile":0.89009}],"urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=1539788","https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdf","https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.46_release_notes","https://security.netapp.com/advisory/ntap-20210129-0001/","https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-17006","description":"In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow."}]},{"artifact":{"id":"991c4985867726c0","cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.23.9-2:*:*:*:*:*:*:*"],"name":"libp11-kit0","purl":"pkg:deb/ubuntu/libp11-kit0@0.23.9-2?arch=amd64&distro=ubuntu-18.04&upstream=p11-kit","type":"deb","version":"0.23.9-2","language":"","licenses":["sha256:077e865058e6f7212e89794c84ca99c3e97b9b10e4d1f8253f93d96825e4f6b0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libp11-kit0/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libp11-kit0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"p11-kit"}]},"matchDetails":[{"fix":{"suggestedVersion":"0.23.9-2ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-29363","versionConstraint":"< 0.23.9-2ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"p11-kit","version":"0.23.9-2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-29363","fix":{"state":"fixed","versions":["0.23.9-2ubuntu0.1"],"available":[{"date":"2021-01-05","kind":"advisory","version":"0.23.9-2ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-29363","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-29363","date":"2026-10-08","epss":0.03528,"percentile":0.88926}],"risk":1.764,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-29363"},"relatedVulnerabilities":[{"id":"CVE-2020-29363","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-29363","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-29363","date":"2026-10-08","epss":0.03528,"percentile":0.88926}],"urls":["https://github.com/p11-glue/p11-kit/releases","https://github.com/p11-glue/p11-kit/security/advisories/GHSA-5j67-fw89-fp6x","https://www.debian.org/security/2021/dsa-4822","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-29363","description":"An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE, the receiving entity may not allocate sufficient length for the buffer to store the deserialized value."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.5+10-0ubuntu1.1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2962","versionConstraint":"< 11.0.5+10-0ubuntu1.1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2962","fix":{"state":"fixed","versions":["11.0.5+10-0ubuntu1.1~18.04"],"available":[{"date":"2019-12-17","kind":"advisory","version":"11.0.5+10-0ubuntu1.1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2962","date":"2026-10-08","epss":0.03517,"percentile":0.88896}],"risk":1.7585,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2962"},"relatedVulnerabilities":[{"id":"CVE-2019-2962","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2962","date":"2026-10-08","epss":0.03517,"percentile":0.88896}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://access.redhat.com/errata/RHSA-2019:3134","https://access.redhat.com/errata/RHSA-2019:3135","https://access.redhat.com/errata/RHSA-2019:3136","https://access.redhat.com/errata/RHSA-2019:3157","https://access.redhat.com/errata/RHSA-2019:3158","https://access.redhat.com/errata/RHSA-2019:4109","https://access.redhat.com/errata/RHSA-2019:4110","https://access.redhat.com/errata/RHSA-2019:4113","https://access.redhat.com/errata/RHSA-2019:4115","https://access.redhat.com/errata/RHSA-2020:0006","https://access.redhat.com/errata/RHSA-2020:0046","https://lists.debian.org/debian-lts-announce/2019/12/msg00005.html","https://seclists.org/bugtraq/2019/Oct/27","https://seclists.org/bugtraq/2019/Oct/31","https://security.netapp.com/advisory/ntap-20191017-0001/","https://usn.ubuntu.com/4223-1/","https://www.debian.org/security/2019/dsa-4546","https://www.debian.org/security/2019/dsa-4548"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2962","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.5+10-0ubuntu1.1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2964","versionConstraint":"< 11.0.5+10-0ubuntu1.1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2964","fix":{"state":"fixed","versions":["11.0.5+10-0ubuntu1.1~18.04"],"available":[{"date":"2019-12-17","kind":"advisory","version":"11.0.5+10-0ubuntu1.1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2964","date":"2026-10-08","epss":0.03517,"percentile":0.88896}],"risk":1.7585,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2964"},"relatedVulnerabilities":[{"id":"CVE-2019-2964","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2964","date":"2026-10-08","epss":0.03517,"percentile":0.88896}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://access.redhat.com/errata/RHSA-2019:3134","https://access.redhat.com/errata/RHSA-2019:3135","https://access.redhat.com/errata/RHSA-2019:3136","https://access.redhat.com/errata/RHSA-2019:3157","https://access.redhat.com/errata/RHSA-2019:3158","https://access.redhat.com/errata/RHSA-2019:4109","https://access.redhat.com/errata/RHSA-2019:4110","https://access.redhat.com/errata/RHSA-2019:4113","https://access.redhat.com/errata/RHSA-2019:4115","https://access.redhat.com/errata/RHSA-2020:0006","https://access.redhat.com/errata/RHSA-2020:0046","https://lists.debian.org/debian-lts-announce/2019/12/msg00005.html","https://seclists.org/bugtraq/2019/Oct/27","https://seclists.org/bugtraq/2019/Oct/31","https://security.netapp.com/advisory/ntap-20191017-0001/","https://usn.ubuntu.com/4223-1/","https://www.debian.org/security/2019/dsa-4546","https://www.debian.org/security/2019/dsa-4548"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2964","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.5+10-0ubuntu1.1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2987","versionConstraint":"< 11.0.5+10-0ubuntu1.1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2987","fix":{"state":"fixed","versions":["11.0.5+10-0ubuntu1.1~18.04"],"available":[{"date":"2019-12-17","kind":"advisory","version":"11.0.5+10-0ubuntu1.1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2987","date":"2026-10-08","epss":0.03517,"percentile":0.88896}],"risk":1.7585,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2987"},"relatedVulnerabilities":[{"id":"CVE-2019-2987","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2987","date":"2026-10-08","epss":0.03517,"percentile":0.88896}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://access.redhat.com/errata/RHSA-2019:3134","https://access.redhat.com/errata/RHSA-2019:3135","https://access.redhat.com/errata/RHSA-2019:3136","https://access.redhat.com/errata/RHSA-2019:3157","https://access.redhat.com/errata/RHSA-2019:3158","https://lists.debian.org/debian-lts-announce/2019/12/msg00005.html","https://seclists.org/bugtraq/2019/Oct/27","https://seclists.org/bugtraq/2019/Oct/31","https://security.netapp.com/advisory/ntap-20191017-0001/","https://usn.ubuntu.com/4223-1/","https://www.debian.org/security/2019/dsa-4546","https://www.debian.org/security/2019/dsa-4548"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2987","description":"Vulnerability in the Java SE product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-18348","versionConstraint":"< 2.7.17-1~18.04ubuntu1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-18348","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1"],"available":[{"date":"2020-04-21","kind":"advisory","version":"2.7.17-1~18.04ubuntu1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-18348","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-18348","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-18348","date":"2026-10-08","epss":0.03513,"percentile":0.88887}],"risk":1.7565000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-18348"},"relatedVulnerabilities":[{"id":"CVE-2019-18348","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-18348","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-18348","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-18348","date":"2026-10-08","epss":0.03513,"percentile":0.88887}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.html","https://bugs.python.org/issue30458#msg347282","https://bugzilla.redhat.com/show_bug.cgi?id=1727276","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5NSAX4SC3V64PGZUPH7PRDLSON34Q5A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UESGYI5XDAHJBATEZN3MHNDUBDH47AS6/","https://security.netapp.com/advisory/ntap-20191107-0004/","https://usn.ubuntu.com/4333-1/","https://usn.ubuntu.com/4333-2/","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-18348","description":"An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \\r\\n (specifically in the host component of a URL) followed by an HTTP header. This is similar to the CVE-2019-9740 query string issue and the CVE-2019-9947 path string issue. (This is not exploitable when glibc has CVE-2016-10739 fixed.). This is fixed in: v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1; v3.6.11, v3.6.11rc1, v3.6.12; v3.7.8, v3.7.8rc1, v3.7.9; v3.8.3, v3.8.3rc1, v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-18348","versionConstraint":"< 2.7.17-1~18.04ubuntu1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-18348","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1"],"available":[{"date":"2020-04-21","kind":"advisory","version":"2.7.17-1~18.04ubuntu1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-18348","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-18348","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-18348","date":"2026-10-08","epss":0.03513,"percentile":0.88887}],"risk":1.7565000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-18348"},"relatedVulnerabilities":[{"id":"CVE-2019-18348","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-18348","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-18348","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-18348","date":"2026-10-08","epss":0.03513,"percentile":0.88887}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.html","https://bugs.python.org/issue30458#msg347282","https://bugzilla.redhat.com/show_bug.cgi?id=1727276","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5NSAX4SC3V64PGZUPH7PRDLSON34Q5A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UESGYI5XDAHJBATEZN3MHNDUBDH47AS6/","https://security.netapp.com/advisory/ntap-20191107-0004/","https://usn.ubuntu.com/4333-1/","https://usn.ubuntu.com/4333-2/","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-18348","description":"An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \\r\\n (specifically in the host component of a URL) followed by an HTTP header. This is similar to the CVE-2019-9740 query string issue and the CVE-2019-9947 path string issue. (This is not exploitable when glibc has CVE-2016-10739 fixed.). This is fixed in: v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1; v3.6.11, v3.6.11rc1, v3.6.12; v3.7.8, v3.7.8rc1, v3.7.9; v3.8.3, v3.8.3rc1, v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-18348","versionConstraint":"< 2.7.17-1~18.04ubuntu1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-18348","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1"],"available":[{"date":"2020-04-21","kind":"advisory","version":"2.7.17-1~18.04ubuntu1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-18348","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-18348","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-18348","date":"2026-10-08","epss":0.03513,"percentile":0.88887}],"risk":1.7565000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-18348"},"relatedVulnerabilities":[{"id":"CVE-2019-18348","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-18348","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-18348","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-18348","date":"2026-10-08","epss":0.03513,"percentile":0.88887}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.html","https://bugs.python.org/issue30458#msg347282","https://bugzilla.redhat.com/show_bug.cgi?id=1727276","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5NSAX4SC3V64PGZUPH7PRDLSON34Q5A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UESGYI5XDAHJBATEZN3MHNDUBDH47AS6/","https://security.netapp.com/advisory/ntap-20191107-0004/","https://usn.ubuntu.com/4333-1/","https://usn.ubuntu.com/4333-2/","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-18348","description":"An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \\r\\n (specifically in the host component of a URL) followed by an HTTP header. This is similar to the CVE-2019-9740 query string issue and the CVE-2019-9947 path string issue. (This is not exploitable when glibc has CVE-2016-10739 fixed.). This is fixed in: v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1; v3.6.11, v3.6.11rc1, v3.6.12; v3.7.8, v3.7.8rc1, v3.7.9; v3.8.3, v3.8.3rc1, v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-18348","versionConstraint":"< 2.7.17-1~18.04ubuntu1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-18348","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1"],"available":[{"date":"2020-04-21","kind":"advisory","version":"2.7.17-1~18.04ubuntu1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-18348","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-18348","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-18348","date":"2026-10-08","epss":0.03513,"percentile":0.88887}],"risk":1.7565000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-18348"},"relatedVulnerabilities":[{"id":"CVE-2019-18348","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-18348","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-18348","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-18348","date":"2026-10-08","epss":0.03513,"percentile":0.88887}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.html","https://bugs.python.org/issue30458#msg347282","https://bugzilla.redhat.com/show_bug.cgi?id=1727276","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5NSAX4SC3V64PGZUPH7PRDLSON34Q5A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UESGYI5XDAHJBATEZN3MHNDUBDH47AS6/","https://security.netapp.com/advisory/ntap-20191107-0004/","https://usn.ubuntu.com/4333-1/","https://usn.ubuntu.com/4333-2/","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-18348","description":"An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \\r\\n (specifically in the host component of a URL) followed by an HTTP header. This is similar to the CVE-2019-9740 query string issue and the CVE-2019-9947 path string issue. (This is not exploitable when glibc has CVE-2016-10739 fixed.). This is fixed in: v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1; v3.6.11, v3.6.11rc1, v3.6.12; v3.7.8, v3.7.8rc1, v3.7.9; v3.8.3, v3.8.3rc1, v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-9143","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-9143","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-9143","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-9143","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-9143","date":"2026-10-08","epss":0.05842,"percentile":0.92986}],"risk":1.7526,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-9143"},"relatedVulnerabilities":[{"id":"CVE-2024-9143","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-9143","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-9143","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-9143","date":"2026-10-08","epss":0.05842,"percentile":0.92986}],"urls":["https://github.com/openssl/openssl/commit/72ae83ad214d2eef262461365a1975707f862712","https://github.com/openssl/openssl/commit/bc7e04d7c8d509fb78fc0e285aa948fb0da04700","https://github.com/openssl/openssl/commit/c0d3e4d32d2805f49bec30547f225bc4d092e1f4","https://github.com/openssl/openssl/commit/fdf6723362ca51bd883295efe206cb5b1cfa5154","https://github.openssl.org/openssl/extended-releases/commit/8efc0cbaa8ebba8e116f7b81a876a4123594d86a","https://github.openssl.org/openssl/extended-releases/commit/9d576994cec2b7aa37a91740ea7e680810957e41","https://openssl-library.org/news/secadv/20241016.txt","http://www.openwall.com/lists/oss-security/2024/10/16/1","http://www.openwall.com/lists/oss-security/2024/10/23/1","http://www.openwall.com/lists/oss-security/2024/10/24/1","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20241101-0001/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-277137.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-9143","description":"Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted\nexplicit values for the field polynomial can lead to out-of-bounds memory reads\nor writes.\n\nImpact summary: Out of bound memory writes can lead to an application crash or\neven a possibility of a remote code execution, however, in all the protocols\ninvolving Elliptic Curve Cryptography that we're aware of, either only \"named\ncurves\" are supported, or, if explicit curve parameters are supported, they\nspecify an X9.62 encoding of binary (GF(2^m)) curves that can't represent\nproblematic input values. Thus the likelihood of existence of a vulnerable\napplication is low.\n\nIn particular, the X9.62 encoding is used for ECC keys in X.509 certificates,\nso problematic inputs cannot occur in the context of processing X.509\ncertificates.  Any problematic use-cases would have to be using an \"exotic\"\ncurve encoding.\n\nThe affected APIs include: EC_GROUP_new_curve_GF2m(), EC_GROUP_new_from_params(),\nand various supporting BN_GF2m_*() functions.\n\nApplications working with \"exotic\" explicit binary (GF(2^m)) curve parameters,\nthat make it possible to represent invalid field polynomials with a zero\nconstant term, via the above or similar APIs, may terminate abruptly as a\nresult of reading or writing outside of array bounds.  Remote code execution\ncannot easily be ruled out.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-9143","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-9143","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-9143","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-9143","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-9143","date":"2026-10-08","epss":0.05842,"percentile":0.92986}],"risk":1.7526,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-9143"},"relatedVulnerabilities":[{"id":"CVE-2024-9143","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-9143","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-9143","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-9143","date":"2026-10-08","epss":0.05842,"percentile":0.92986}],"urls":["https://github.com/openssl/openssl/commit/72ae83ad214d2eef262461365a1975707f862712","https://github.com/openssl/openssl/commit/bc7e04d7c8d509fb78fc0e285aa948fb0da04700","https://github.com/openssl/openssl/commit/c0d3e4d32d2805f49bec30547f225bc4d092e1f4","https://github.com/openssl/openssl/commit/fdf6723362ca51bd883295efe206cb5b1cfa5154","https://github.openssl.org/openssl/extended-releases/commit/8efc0cbaa8ebba8e116f7b81a876a4123594d86a","https://github.openssl.org/openssl/extended-releases/commit/9d576994cec2b7aa37a91740ea7e680810957e41","https://openssl-library.org/news/secadv/20241016.txt","http://www.openwall.com/lists/oss-security/2024/10/16/1","http://www.openwall.com/lists/oss-security/2024/10/23/1","http://www.openwall.com/lists/oss-security/2024/10/24/1","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20241101-0001/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-277137.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-9143","description":"Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted\nexplicit values for the field polynomial can lead to out-of-bounds memory reads\nor writes.\n\nImpact summary: Out of bound memory writes can lead to an application crash or\neven a possibility of a remote code execution, however, in all the protocols\ninvolving Elliptic Curve Cryptography that we're aware of, either only \"named\ncurves\" are supported, or, if explicit curve parameters are supported, they\nspecify an X9.62 encoding of binary (GF(2^m)) curves that can't represent\nproblematic input values. Thus the likelihood of existence of a vulnerable\napplication is low.\n\nIn particular, the X9.62 encoding is used for ECC keys in X.509 certificates,\nso problematic inputs cannot occur in the context of processing X.509\ncertificates.  Any problematic use-cases would have to be using an \"exotic\"\ncurve encoding.\n\nThe affected APIs include: EC_GROUP_new_curve_GF2m(), EC_GROUP_new_from_params(),\nand various supporting BN_GF2m_*() functions.\n\nApplications working with \"exotic\" explicit binary (GF(2^m)) curve parameters,\nthat make it possible to represent invalid field polynomials with a zero\nconstant term, via the above or similar APIs, may terminate abruptly as a\nresult of reading or writing outside of array bounds.  Remote code execution\ncannot easily be ruled out.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21360","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21360","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21360","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21360","date":"2026-10-08","epss":0.03486,"percentile":0.88802}],"risk":1.743,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21360"},"relatedVulnerabilities":[{"id":"CVE-2022-21360","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21360","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21360","date":"2026-10-08","epss":0.03486,"percentile":0.88802}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21360","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21365","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21365","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2022-21365","date":"2026-10-08","epss":0.03486,"percentile":0.88802}],"risk":1.743,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21365"},"relatedVulnerabilities":[{"id":"CVE-2022-21365","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-21365","date":"2026-10-08","epss":0.03486,"percentile":0.88802}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21365","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21299","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21299","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21299","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21299","date":"2026-10-08","epss":0.03458,"percentile":0.88709}],"risk":1.729,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21299"},"relatedVulnerabilities":[{"id":"CVE-2022-21299","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21299","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21299","date":"2026-10-08","epss":0.03458,"percentile":0.88709}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21299","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.5+10-0ubuntu1.1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2992","versionConstraint":"< 11.0.5+10-0ubuntu1.1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2992","fix":{"state":"fixed","versions":["11.0.5+10-0ubuntu1.1~18.04"],"available":[{"date":"2019-12-17","kind":"advisory","version":"11.0.5+10-0ubuntu1.1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2992","date":"2026-10-08","epss":0.03452,"percentile":0.88689}],"risk":1.7260000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2992"},"relatedVulnerabilities":[{"id":"CVE-2019-2992","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2992","date":"2026-10-08","epss":0.03452,"percentile":0.88689}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://access.redhat.com/errata/RHSA-2019:3134","https://access.redhat.com/errata/RHSA-2019:3135","https://access.redhat.com/errata/RHSA-2019:3136","https://access.redhat.com/errata/RHSA-2019:3157","https://access.redhat.com/errata/RHSA-2019:3158","https://access.redhat.com/errata/RHSA-2019:4109","https://access.redhat.com/errata/RHSA-2019:4110","https://access.redhat.com/errata/RHSA-2019:4113","https://access.redhat.com/errata/RHSA-2019:4115","https://access.redhat.com/errata/RHSA-2020:0006","https://access.redhat.com/errata/RHSA-2020:0046","https://lists.debian.org/debian-lts-announce/2019/12/msg00005.html","https://seclists.org/bugtraq/2019/Oct/27","https://seclists.org/bugtraq/2019/Oct/31","https://security.netapp.com/advisory/ntap-20191017-0001/","https://usn.ubuntu.com/4223-1/","https://www.debian.org/security/2019/dsa-4546","https://www.debian.org/security/2019/dsa-4548"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2992","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-2369","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-2369","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-2369","date":"2026-10-08","epss":0.03444,"percentile":0.88668}],"risk":1.722,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-2369"},"relatedVulnerabilities":[{"id":"CVE-2021-2369","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-2369","date":"2026-10-08","epss":0.03444,"percentile":0.88668}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1982879","https://lists.debian.org/debian-lts-announce/2021/08/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20210723-0002/","https://www.debian.org/security/2021/dsa-4946","https://www.oracle.com/security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-2369","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Library). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1543","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-1543","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.2"],"available":[{"date":"2019-03-06","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-1543","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-1543","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1543","date":"2026-10-08","epss":0.05701,"percentile":0.92815}],"risk":1.7103,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1543"},"relatedVulnerabilities":[{"id":"CVE-2019-1543","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1543","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-1543","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1543","date":"2026-10-08","epss":0.05701,"percentile":0.92815}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.html","https://access.redhat.com/errata/RHSA-2019:3700","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ee22257b1418438ebaf54df98af4e24f494d1809","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=f426625b6ae9a7831010750490a5f0ad689c5ba3","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/","https://seclists.org/bugtraq/2019/Jul/3","https://www.debian.org/security/2019/dsa-4475","https://www.openssl.org/news/secadv/20190306.txt","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1543","description":"ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation. RFC 7539 specifies that the nonce value (IV) should be 96 bits (12 bytes). OpenSSL allows a variable nonce length and front pads the nonce with 0 bytes if it is less than 12 bytes. However it also incorrectly allows a nonce to be set of up to 16 bytes. In this case only the last 12 bytes are significant and any additional leading bytes are ignored. It is a requirement of using this cipher that nonce values are unique. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks. If an application changes the default nonce length to be longer than 12 bytes and then makes a change to the leading bytes of the nonce expecting the new value to be a new unique nonce then such an application could inadvertently encrypt messages with a reused nonce. Additionally the ignored bytes in a long nonce are not covered by the integrity guarantee of this cipher. Any application that relies on the integrity of these ignored leading bytes of a long nonce may be further affected. Any OpenSSL internal use of this cipher, including in SSL/TLS, is safe because no such use sets such a long nonce value. However user applications that use this cipher directly and set a non-default nonce length to be longer than 12 bytes may be vulnerable. OpenSSL versions 1.1.1 and 1.1.0 are affected by this issue. Due to the limited scope of affected deployments this has been assessed as low severity and therefore we are not creating new releases at this time. Fixed in OpenSSL 1.1.1c (Affected 1.1.1-1.1.1b). Fixed in OpenSSL 1.1.0k (Affected 1.1.0-1.1.0j)."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-1543","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-1543","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.2"],"available":[{"date":"2019-03-06","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-1543","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-1543","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1543","date":"2026-10-08","epss":0.05701,"percentile":0.92815}],"risk":1.7103,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1543"},"relatedVulnerabilities":[{"id":"CVE-2019-1543","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1543","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-1543","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1543","date":"2026-10-08","epss":0.05701,"percentile":0.92815}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.html","https://access.redhat.com/errata/RHSA-2019:3700","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ee22257b1418438ebaf54df98af4e24f494d1809","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=f426625b6ae9a7831010750490a5f0ad689c5ba3","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/","https://seclists.org/bugtraq/2019/Jul/3","https://www.debian.org/security/2019/dsa-4475","https://www.openssl.org/news/secadv/20190306.txt","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1543","description":"ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation. RFC 7539 specifies that the nonce value (IV) should be 96 bits (12 bytes). OpenSSL allows a variable nonce length and front pads the nonce with 0 bytes if it is less than 12 bytes. However it also incorrectly allows a nonce to be set of up to 16 bytes. In this case only the last 12 bytes are significant and any additional leading bytes are ignored. It is a requirement of using this cipher that nonce values are unique. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks. If an application changes the default nonce length to be longer than 12 bytes and then makes a change to the leading bytes of the nonce expecting the new value to be a new unique nonce then such an application could inadvertently encrypt messages with a reused nonce. Additionally the ignored bytes in a long nonce are not covered by the integrity guarantee of this cipher. Any application that relies on the integrity of these ignored leading bytes of a long nonce may be further affected. Any OpenSSL internal use of this cipher, including in SSL/TLS, is safe because no such use sets such a long nonce value. However user applications that use this cipher directly and set a non-default nonce length to be longer than 12 bytes may be vulnerable. OpenSSL versions 1.1.1 and 1.1.0 are affected by this issue. Due to the limited scope of affected deployments this has been assessed as low severity and therefore we are not creating new releases at this time. Fixed in OpenSSL 1.1.1c (Affected 1.1.1-1.1.1b). Fixed in OpenSSL 1.1.0k (Affected 1.1.0-1.1.0j)."}]},{"artifact":{"id":"88bdd6da7cccc159","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-22823","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-22823","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-22823","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22823","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22823","date":"2026-10-08","epss":0.03404,"percentile":0.88532}],"risk":1.702,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-22823"},"relatedVulnerabilities":[{"id":"CVE-2022-22823","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22823","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22823","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22823","date":"2026-10-08","epss":0.03404,"percentile":0.88532}],"urls":["http://www.openwall.com/lists/oss-security/2022/01/17/3","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/539","https://security.gentoo.org/glsa/202209-24","https://www.debian.org/security/2022/dsa-5073","https://www.tenable.com/security/tns-2022-05"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22823","description":"build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow."}]},{"artifact":{"id":"88bdd6da7cccc159","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-22824","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-22824","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-22824","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22824","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22824","date":"2026-10-08","epss":0.03404,"percentile":0.88532}],"risk":1.702,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-22824"},"relatedVulnerabilities":[{"id":"CVE-2022-22824","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22824","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22824","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22824","date":"2026-10-08","epss":0.03404,"percentile":0.88532}],"urls":["http://www.openwall.com/lists/oss-security/2022/01/17/3","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/539","https://security.gentoo.org/glsa/202209-24","https://www.debian.org/security/2022/dsa-5073","https://www.tenable.com/security/tns-2022-05"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22824","description":"defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.8+10-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14577","versionConstraint":"< 11.0.8+10-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14577","fix":{"state":"fixed","versions":["11.0.8+10-0ubuntu1~18.04.1"],"available":[{"date":"2020-07-23","kind":"advisory","version":"11.0.8+10-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14577","date":"2026-10-08","epss":0.0338,"percentile":0.88451}],"risk":1.69,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14577"},"relatedVulnerabilities":[{"id":"CVE-2020-14577","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14577","date":"2026-10-08","epss":0.0338,"percentile":0.88451}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html","http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CFJPOYF3CWYEPCDOAOCNFJTQIKKWPHW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFZ36XIW5ENQAW6BB7WHRFFTTJX7KGMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200717-0005/","https://usn.ubuntu.com/4433-1/","https://usn.ubuntu.com/4453-1/","https://www.debian.org/security/2020/dsa-4734","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14577","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.8+10-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14573","versionConstraint":"< 11.0.8+10-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14573","fix":{"state":"fixed","versions":["11.0.8+10-0ubuntu1~18.04.1"],"available":[{"date":"2020-07-23","kind":"advisory","version":"11.0.8+10-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14573","date":"2026-10-08","epss":0.03377,"percentile":0.88441}],"risk":1.6885000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14573"},"relatedVulnerabilities":[{"id":"CVE-2020-14573","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14573","date":"2026-10-08","epss":0.03377,"percentile":0.88441}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html","https://kc.mcafee.com/corporate/index?page=content&id=SB10332","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/","https://security.gentoo.org/glsa/202008-24","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200717-0005/","https://usn.ubuntu.com/4433-1/","https://www.debian.org/security/2020/dsa-4734","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14573","description":"Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"991c4985867726c0","cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.23.9-2:*:*:*:*:*:*:*"],"name":"libp11-kit0","purl":"pkg:deb/ubuntu/libp11-kit0@0.23.9-2?arch=amd64&distro=ubuntu-18.04&upstream=p11-kit","type":"deb","version":"0.23.9-2","language":"","licenses":["sha256:077e865058e6f7212e89794c84ca99c3e97b9b10e4d1f8253f93d96825e4f6b0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libp11-kit0/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libp11-kit0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"p11-kit"}]},"matchDetails":[{"fix":{"suggestedVersion":"0.23.9-2ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-29361","versionConstraint":"< 0.23.9-2ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"p11-kit","version":"0.23.9-2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-29361","fix":{"state":"fixed","versions":["0.23.9-2ubuntu0.1"],"available":[{"date":"2021-01-05","kind":"advisory","version":"0.23.9-2ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-29361","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-29361","date":"2026-10-08","epss":0.03363,"percentile":0.88395}],"risk":1.6815,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-29361"},"relatedVulnerabilities":[{"id":"CVE-2020-29361","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-29361","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-29361","date":"2026-10-08","epss":0.03363,"percentile":0.88395}],"urls":["https://github.com/p11-glue/p11-kit/releases","https://github.com/p11-glue/p11-kit/security/advisories/GHSA-q4r3-hm6m-mvc2","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/01/msg00002.html","https://www.debian.org/security/2021/dsa-4822"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-29361","description":"An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21294","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21294","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21294","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21294","date":"2026-10-08","epss":0.0335,"percentile":0.88351}],"risk":1.675,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21294"},"relatedVulnerabilities":[{"id":"CVE-2022-21294","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21294","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21294","date":"2026-10-08","epss":0.0335,"percentile":0.88351}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21294","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"c46476e0cbe7f54c","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-5535","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-5535","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-5535","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-5535","date":"2026-10-08","epss":0.05582,"percentile":0.92684}],"risk":1.6746,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-5535"},"relatedVulnerabilities":[{"id":"CVE-2024-5535","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-5535","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-5535","date":"2026-10-08","epss":0.05582,"percentile":0.92684}],"urls":["https://github.com/openssl/openssl/commit/4ada436a1946cbb24db5ab4ca082b69c1bc10f37","https://github.com/openssl/openssl/commit/99fb785a5f85315b95288921a321a935ea29a51e","https://github.com/openssl/openssl/commit/cf6f91f6121f4db167405db2f0de410a456f260c","https://github.com/openssl/openssl/commit/e86ac436f0bd54d4517745483e2315650fae7b2c","https://github.openssl.org/openssl/extended-releases/commit/9947251413065a05189a63c9b7a6c1d4e224c21c","https://github.openssl.org/openssl/extended-releases/commit/b78ec0824da857223486660177d3b1f255c65d87","https://www.openssl.org/news/secadv/20240627.txt","http://www.openwall.com/lists/oss-security/2024/06/27/1","http://www.openwall.com/lists/oss-security/2024/06/28/4","http://www.openwall.com/lists/oss-security/2024/08/15/1","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20240712-0005/","https://security.netapp.com/advisory/ntap-20241025-0006/","https://security.netapp.com/advisory/ntap-20241025-0010/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-277137.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-5535","description":"Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an\nempty supported client protocols buffer may cause a crash or memory contents to\nbe sent to the peer.\n\nImpact summary: A buffer overread can have a range of potential consequences\nsuch as unexpected application beahviour or a crash. In particular this issue\ncould result in up to 255 bytes of arbitrary private data from memory being sent\nto the peer leading to a loss of confidentiality. However, only applications\nthat directly call the SSL_select_next_proto function with a 0 length list of\nsupported client protocols are affected by this issue. This would normally never\nbe a valid scenario and is typically not under attacker control but may occur by\naccident in the case of a configuration or programming error in the calling\napplication.\n\nThe OpenSSL API function SSL_select_next_proto is typically used by TLS\napplications that support ALPN (Application Layer Protocol Negotiation) or NPN\n(Next Protocol Negotiation). NPN is older, was never standardised and\nis deprecated in favour of ALPN. We believe that ALPN is significantly more\nwidely deployed than NPN. The SSL_select_next_proto function accepts a list of\nprotocols from the server and a list of protocols from the client and returns\nthe first protocol that appears in the server list that also appears in the\nclient list. In the case of no overlap between the two lists it returns the\nfirst item in the client list. In either case it will signal whether an overlap\nbetween the two lists was found. In the case where SSL_select_next_proto is\ncalled with a zero length client list it fails to notice this condition and\nreturns the memory immediately following the client list pointer (and reports\nthat there was no overlap in the lists).\n\nThis function is typically called from a server side application callback for\nALPN or a client side application callback for NPN. In the case of ALPN the list\nof protocols supplied by the client is guaranteed by libssl to never be zero in\nlength. The list of server protocols comes from the application and should never\nnormally be expected to be of zero length. In this case if the\nSSL_select_next_proto function has been called as expected (with the list\nsupplied by the client passed in the client/client_len parameters), then the\napplication will not be vulnerable to this issue. If the application has\naccidentally been configured with a zero length server list, and has\naccidentally passed that zero length server list in the client/client_len\nparameters, and has additionally failed to correctly handle a \"no overlap\"\nresponse (which would normally result in a handshake failure in ALPN) then it\nwill be vulnerable to this problem.\n\nIn the case of NPN, the protocol permits the client to opportunistically select\na protocol when there is no overlap. OpenSSL returns the first client protocol\nin the no overlap case in support of this. The list of client protocols comes\nfrom the application and should never normally be expected to be of zero length.\nHowever if the SSL_select_next_proto function is accidentally called with a\nclient_len of 0 then an invalid memory pointer will be returned instead. If the\napplication uses this output as the opportunistic protocol then the loss of\nconfidentiality will occur.\n\nThis issue has been assessed as Low severity because applications are most\nlikely to be vulnerable if they are using NPN instead of ALPN - but NPN is not\nwidely used. It also requires an application configuration or programming error.\nFinally, this issue would not typically be under attacker control making active\nexploitation unlikely.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.\n\nDue to the low severity of this issue we are not issuing new releases of\nOpenSSL at this time. The fix will be included in the next releases when they\nbecome available."}]},{"artifact":{"id":"61282a0973bcd95e","cpes":["cpe:2.3:a:openssl:openssl:1.1.0g-2ubuntu4.3:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.0g-2ubuntu4.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.0g-2ubuntu4.3","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-5535","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.0g-2ubuntu4.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-5535","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-5535","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-5535","date":"2026-10-08","epss":0.05582,"percentile":0.92684}],"risk":1.6746,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-5535"},"relatedVulnerabilities":[{"id":"CVE-2024-5535","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-5535","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-5535","date":"2026-10-08","epss":0.05582,"percentile":0.92684}],"urls":["https://github.com/openssl/openssl/commit/4ada436a1946cbb24db5ab4ca082b69c1bc10f37","https://github.com/openssl/openssl/commit/99fb785a5f85315b95288921a321a935ea29a51e","https://github.com/openssl/openssl/commit/cf6f91f6121f4db167405db2f0de410a456f260c","https://github.com/openssl/openssl/commit/e86ac436f0bd54d4517745483e2315650fae7b2c","https://github.openssl.org/openssl/extended-releases/commit/9947251413065a05189a63c9b7a6c1d4e224c21c","https://github.openssl.org/openssl/extended-releases/commit/b78ec0824da857223486660177d3b1f255c65d87","https://www.openssl.org/news/secadv/20240627.txt","http://www.openwall.com/lists/oss-security/2024/06/27/1","http://www.openwall.com/lists/oss-security/2024/06/28/4","http://www.openwall.com/lists/oss-security/2024/08/15/1","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20240712-0005/","https://security.netapp.com/advisory/ntap-20241025-0006/","https://security.netapp.com/advisory/ntap-20241025-0010/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-277137.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-5535","description":"Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an\nempty supported client protocols buffer may cause a crash or memory contents to\nbe sent to the peer.\n\nImpact summary: A buffer overread can have a range of potential consequences\nsuch as unexpected application beahviour or a crash. In particular this issue\ncould result in up to 255 bytes of arbitrary private data from memory being sent\nto the peer leading to a loss of confidentiality. However, only applications\nthat directly call the SSL_select_next_proto function with a 0 length list of\nsupported client protocols are affected by this issue. This would normally never\nbe a valid scenario and is typically not under attacker control but may occur by\naccident in the case of a configuration or programming error in the calling\napplication.\n\nThe OpenSSL API function SSL_select_next_proto is typically used by TLS\napplications that support ALPN (Application Layer Protocol Negotiation) or NPN\n(Next Protocol Negotiation). NPN is older, was never standardised and\nis deprecated in favour of ALPN. We believe that ALPN is significantly more\nwidely deployed than NPN. The SSL_select_next_proto function accepts a list of\nprotocols from the server and a list of protocols from the client and returns\nthe first protocol that appears in the server list that also appears in the\nclient list. In the case of no overlap between the two lists it returns the\nfirst item in the client list. In either case it will signal whether an overlap\nbetween the two lists was found. In the case where SSL_select_next_proto is\ncalled with a zero length client list it fails to notice this condition and\nreturns the memory immediately following the client list pointer (and reports\nthat there was no overlap in the lists).\n\nThis function is typically called from a server side application callback for\nALPN or a client side application callback for NPN. In the case of ALPN the list\nof protocols supplied by the client is guaranteed by libssl to never be zero in\nlength. The list of server protocols comes from the application and should never\nnormally be expected to be of zero length. In this case if the\nSSL_select_next_proto function has been called as expected (with the list\nsupplied by the client passed in the client/client_len parameters), then the\napplication will not be vulnerable to this issue. If the application has\naccidentally been configured with a zero length server list, and has\naccidentally passed that zero length server list in the client/client_len\nparameters, and has additionally failed to correctly handle a \"no overlap\"\nresponse (which would normally result in a handshake failure in ALPN) then it\nwill be vulnerable to this problem.\n\nIn the case of NPN, the protocol permits the client to opportunistically select\na protocol when there is no overlap. OpenSSL returns the first client protocol\nin the no overlap case in support of this. The list of client protocols comes\nfrom the application and should never normally be expected to be of zero length.\nHowever if the SSL_select_next_proto function is accidentally called with a\nclient_len of 0 then an invalid memory pointer will be returned instead. If the\napplication uses this output as the opportunistic protocol then the loss of\nconfidentiality will occur.\n\nThis issue has been assessed as Low severity because applications are most\nlikely to be vulnerable if they are using NPN instead of ALPN - but NPN is not\nwidely used. It also requires an application configuration or programming error.\nFinally, this issue would not typically be under attacker control making active\nexploitation unlikely.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.\n\nDue to the low severity of this issue we are not issuing new releases of\nOpenSSL at this time. The fix will be included in the next releases when they\nbecome available."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.5+10-0ubuntu1.1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2975","versionConstraint":"< 11.0.5+10-0ubuntu1.1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2975","fix":{"state":"fixed","versions":["11.0.5+10-0ubuntu1.1~18.04"],"available":[{"date":"2019-12-17","kind":"advisory","version":"11.0.5+10-0ubuntu1.1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2975","date":"2026-10-08","epss":0.03313,"percentile":0.88226}],"risk":1.6565,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2975"},"relatedVulnerabilities":[{"id":"CVE-2019-2975","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2975","date":"2026-10-08","epss":0.03313,"percentile":0.88226}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://access.redhat.com/errata/RHSA-2019:3134","https://access.redhat.com/errata/RHSA-2019:3135","https://access.redhat.com/errata/RHSA-2019:3136","https://access.redhat.com/errata/RHSA-2019:4113","https://access.redhat.com/errata/RHSA-2019:4115","https://access.redhat.com/errata/RHSA-2020:0006","https://access.redhat.com/errata/RHSA-2020:0046","https://kc.mcafee.com/corporate/index?page=content&id=SB10315","https://seclists.org/bugtraq/2019/Oct/27","https://seclists.org/bugtraq/2019/Oct/31","https://security.netapp.com/advisory/ntap-20191017-0001/","https://usn.ubuntu.com/4223-1/","https://www.debian.org/security/2019/dsa-4546","https://www.debian.org/security/2019/dsa-4548"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2975","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 4.8 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)."}]},{"artifact":{"id":"88bdd6da7cccc159","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-25313","versionConstraint":"< 2.2.5-3ubuntu0.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-25313","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.7"],"available":[{"date":"2022-03-10","kind":"advisory","version":"2.2.5-3ubuntu0.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-25313","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25313","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25313","date":"2026-10-08","epss":0.03295,"percentile":0.88164}],"risk":1.6475,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-25313"},"relatedVulnerabilities":[{"id":"CVE-2022-25313","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25313","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25313","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25313","date":"2026-10-08","epss":0.03295,"percentile":0.88164}],"urls":["http://www.openwall.com/lists/oss-security/2022/02/19/1","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/558","https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/","https://security.gentoo.org/glsa/202209-24","https://security.netapp.com/advisory/ntap-20220303-0008/","https://www.debian.org/security/2022/dsa-5085","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25313","description":"In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.8+10-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14581","versionConstraint":"< 11.0.8+10-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14581","fix":{"state":"fixed","versions":["11.0.8+10-0ubuntu1~18.04.1"],"available":[{"date":"2020-07-23","kind":"advisory","version":"11.0.8+10-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14581","date":"2026-10-08","epss":0.03284,"percentile":0.88115}],"risk":1.6420000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14581"},"relatedVulnerabilities":[{"id":"CVE-2020-14581","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14581","date":"2026-10-08","epss":0.03284,"percentile":0.88115}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html","http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://kc.mcafee.com/corporate/index?page=content&id=SB10332","https://lists.debian.org/debian-lts-announce/2020/08/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CFJPOYF3CWYEPCDOAOCNFJTQIKKWPHW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFZ36XIW5ENQAW6BB7WHRFFTTJX7KGMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200717-0005/","https://usn.ubuntu.com/4433-1/","https://usn.ubuntu.com/4453-1/","https://www.debian.org/security/2020/dsa-4734","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14581","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.5+10-0ubuntu1.1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2945","versionConstraint":"< 11.0.5+10-0ubuntu1.1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2945","fix":{"state":"fixed","versions":["11.0.5+10-0ubuntu1.1~18.04"],"available":[{"date":"2019-12-17","kind":"advisory","version":"11.0.5+10-0ubuntu1.1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2945","date":"2026-10-08","epss":0.03271,"percentile":0.88067}],"risk":1.6355000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2945"},"relatedVulnerabilities":[{"id":"CVE-2019-2945","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2945","date":"2026-10-08","epss":0.03271,"percentile":0.88067}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://access.redhat.com/errata/RHSA-2019:3134","https://access.redhat.com/errata/RHSA-2019:3135","https://access.redhat.com/errata/RHSA-2019:3136","https://access.redhat.com/errata/RHSA-2019:3157","https://access.redhat.com/errata/RHSA-2019:3158","https://access.redhat.com/errata/RHSA-2019:4109","https://access.redhat.com/errata/RHSA-2019:4110","https://access.redhat.com/errata/RHSA-2019:4113","https://access.redhat.com/errata/RHSA-2019:4115","https://access.redhat.com/errata/RHSA-2020:0006","https://access.redhat.com/errata/RHSA-2020:0046","https://lists.debian.org/debian-lts-announce/2019/12/msg00005.html","https://seclists.org/bugtraq/2019/Oct/27","https://seclists.org/bugtraq/2019/Oct/31","https://security.netapp.com/advisory/ntap-20191017-0001/","https://usn.ubuntu.com/4223-1/","https://www.debian.org/security/2019/dsa-4546","https://www.debian.org/security/2019/dsa-4548"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2945","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.5+10-0ubuntu1.1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2988","versionConstraint":"< 11.0.5+10-0ubuntu1.1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2988","fix":{"state":"fixed","versions":["11.0.5+10-0ubuntu1.1~18.04"],"available":[{"date":"2019-12-17","kind":"advisory","version":"11.0.5+10-0ubuntu1.1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2988","date":"2026-10-08","epss":0.03269,"percentile":0.88055}],"risk":1.6344999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2988"},"relatedVulnerabilities":[{"id":"CVE-2019-2988","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2988","date":"2026-10-08","epss":0.03269,"percentile":0.88055}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://access.redhat.com/errata/RHSA-2019:3134","https://access.redhat.com/errata/RHSA-2019:3135","https://access.redhat.com/errata/RHSA-2019:3136","https://access.redhat.com/errata/RHSA-2019:3157","https://access.redhat.com/errata/RHSA-2019:3158","https://access.redhat.com/errata/RHSA-2019:4109","https://access.redhat.com/errata/RHSA-2019:4110","https://access.redhat.com/errata/RHSA-2019:4113","https://access.redhat.com/errata/RHSA-2019:4115","https://access.redhat.com/errata/RHSA-2020:0006","https://access.redhat.com/errata/RHSA-2020:0046","https://lists.debian.org/debian-lts-announce/2019/12/msg00005.html","https://seclists.org/bugtraq/2019/Oct/27","https://seclists.org/bugtraq/2019/Oct/31","https://security.netapp.com/advisory/ntap-20191017-0001/","https://usn.ubuntu.com/4223-1/","https://www.debian.org/security/2019/dsa-4546","https://www.debian.org/security/2019/dsa-4548"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2988","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.5+10-0ubuntu1.1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2978","versionConstraint":"< 11.0.5+10-0ubuntu1.1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2978","fix":{"state":"fixed","versions":["11.0.5+10-0ubuntu1.1~18.04"],"available":[{"date":"2019-12-17","kind":"advisory","version":"11.0.5+10-0ubuntu1.1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2978","date":"2026-10-08","epss":0.03269,"percentile":0.88054}],"risk":1.6344999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2978"},"relatedVulnerabilities":[{"id":"CVE-2019-2978","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2978","date":"2026-10-08","epss":0.03269,"percentile":0.88054}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://access.redhat.com/errata/RHSA-2019:3134","https://access.redhat.com/errata/RHSA-2019:3135","https://access.redhat.com/errata/RHSA-2019:3136","https://access.redhat.com/errata/RHSA-2019:3157","https://access.redhat.com/errata/RHSA-2019:3158","https://access.redhat.com/errata/RHSA-2019:4109","https://access.redhat.com/errata/RHSA-2019:4110","https://access.redhat.com/errata/RHSA-2019:4113","https://access.redhat.com/errata/RHSA-2019:4115","https://access.redhat.com/errata/RHSA-2020:0006","https://access.redhat.com/errata/RHSA-2020:0046","https://lists.debian.org/debian-lts-announce/2019/12/msg00005.html","https://seclists.org/bugtraq/2019/Oct/27","https://seclists.org/bugtraq/2019/Oct/31","https://security.netapp.com/advisory/ntap-20191017-0001/","https://usn.ubuntu.com/4223-1/","https://www.debian.org/security/2019/dsa-4546","https://www.debian.org/security/2019/dsa-4548"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2978","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"2ff00593b3bc3df7","cpes":["cpe:2.3:a:dpkg:dpkg:1.19.0.5ubuntu2.1:*:*:*:*:*:*:*"],"name":"dpkg","purl":"pkg:deb/ubuntu/dpkg@1.19.0.5ubuntu2.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.19.0.5ubuntu2.1","language":"","licenses":["BSD-2-clause","GPL-2","GPL-2+","public-domain-md5","public-domain-s-s-d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dpkg/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/dpkg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dpkg.conffiles","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/dpkg.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dpkg.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/dpkg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dpkg.list","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/dpkg.list"},{"path":"/var/lib/dpkg/info/dpkg.postinst","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/dpkg.postinst"},{"path":"/var/lib/dpkg/info/dpkg.postrm","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/dpkg.postrm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.19.0.5ubuntu2.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-1664","versionConstraint":"< 1.19.0.5ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"dpkg","version":"1.19.0.5ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-1664","fix":{"state":"fixed","versions":["1.19.0.5ubuntu2.4"],"available":[{"date":"2022-05-26","kind":"advisory","version":"1.19.0.5ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-1664","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1664","date":"2026-10-08","epss":0.0324,"percentile":0.87919}],"risk":1.6199999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1664"},"relatedVulnerabilities":[{"id":"CVE-2022-1664","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1664","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1664","date":"2026-10-08","epss":0.0324,"percentile":0.87919}],"urls":["https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=1f23dddc17f69c9598477098c7fb9936e15fa495","https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=58814cacee39c4ce9e2cd0e3a3b9b57ad437eff5","https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=7a6c03cb34d4a09f35df2f10779cbf1b70a5200b","https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=faa4c92debe45412bfcf8a44f26e827800bb24be","https://lists.debian.org/debian-lts-announce/2022/05/msg00033.html","https://lists.debian.org/debian-security-announce/2022/msg00115.html","https://security.netapp.com/advisory/ntap-20221007-0002/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1664","description":"Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.5+10-0ubuntu1.1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2989","versionConstraint":"< 11.0.5+10-0ubuntu1.1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2989","fix":{"state":"fixed","versions":["11.0.5+10-0ubuntu1.1~18.04"],"available":[{"date":"2019-12-17","kind":"advisory","version":"11.0.5+10-0ubuntu1.1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2989","date":"2026-10-08","epss":0.03224,"percentile":0.87868}],"risk":1.6119999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2989"},"relatedVulnerabilities":[{"id":"CVE-2019-2989","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2989","date":"2026-10-08","epss":0.03224,"percentile":0.87868}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://access.redhat.com/errata/RHSA-2019:3134","https://access.redhat.com/errata/RHSA-2019:3135","https://access.redhat.com/errata/RHSA-2019:3136","https://access.redhat.com/errata/RHSA-2019:3157","https://access.redhat.com/errata/RHSA-2019:3158","https://access.redhat.com/errata/RHSA-2019:4109","https://access.redhat.com/errata/RHSA-2019:4110","https://access.redhat.com/errata/RHSA-2019:4113","https://access.redhat.com/errata/RHSA-2019:4115","https://access.redhat.com/errata/RHSA-2020:0006","https://access.redhat.com/errata/RHSA-2020:0046","https://kc.mcafee.com/corporate/index?page=content&id=SB10315","https://lists.debian.org/debian-lts-announce/2019/12/msg00005.html","https://seclists.org/bugtraq/2019/Oct/27","https://seclists.org/bugtraq/2019/Oct/31","https://security.netapp.com/advisory/ntap-20191017-0001/","https://usn.ubuntu.com/4223-1/","https://www.debian.org/security/2019/dsa-4546","https://www.debian.org/security/2019/dsa-4548"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2989","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS v3.0 Base Score 6.8 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N)."}]},{"artifact":{"id":"86469caa4d25f98f","cpes":["cpe:2.3:a:liblz4-1:liblz4-1:0.0\\~r131-2ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:liblz4-1:liblz4_1:0.0\\~r131-2ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:liblz4_1:liblz4-1:0.0\\~r131-2ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:liblz4_1:liblz4_1:0.0\\~r131-2ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:liblz4:liblz4-1:0.0\\~r131-2ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:liblz4:liblz4_1:0.0\\~r131-2ubuntu3:*:*:*:*:*:*:*"],"name":"liblz4-1","purl":"pkg:deb/ubuntu/liblz4-1@0.0~r131-2ubuntu3?arch=amd64&distro=ubuntu-18.04&upstream=lz4","type":"deb","version":"0.0~r131-2ubuntu3","language":"","licenses":["BSD-2-clause","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblz4-1/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/liblz4-1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblz4-1:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/liblz4-1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"lz4"}]},"matchDetails":[{"fix":{"suggestedVersion":"0.0~r131-2ubuntu3.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3520","versionConstraint":"< 0.0~r131-2ubuntu3.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"lz4","version":"0.0~r131-2ubuntu3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3520","fix":{"state":"fixed","versions":["0.0~r131-2ubuntu3.1"],"available":[{"date":"2021-05-26","kind":"advisory","version":"0.0~r131-2ubuntu3.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3520","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3520","cwe":"CWE-190","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3520","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3520","date":"2026-10-08","epss":0.03216,"percentile":0.87832}],"risk":1.608,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3520"},"relatedVulnerabilities":[{"id":"CVE-2021-3520","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3520","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3520","cwe":"CWE-190","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3520","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3520","date":"2026-10-08","epss":0.03216,"percentile":0.87832}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1954559","https://security.netapp.com/advisory/ntap-20211104-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3520","description":"There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21366","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21366","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21366","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21366","date":"2026-10-08","epss":0.03216,"percentile":0.87832}],"risk":1.608,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21366"},"relatedVulnerabilities":[{"id":"CVE-2022-21366","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21366","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21366","date":"2026-10-08","epss":0.03216,"percentile":0.87832}],"urls":["https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21366","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"685ff832fa5df143","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-6096","versionConstraint":"< 2.27-3ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-6096","fix":{"state":"fixed","versions":["2.27-3ubuntu1.5"],"available":[{"date":"2022-03-01","kind":"advisory","version":"2.27-3ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-08","epss":0.05354,"percentile":0.92432}],"risk":1.6062,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-6096"},"relatedVulnerabilities":[{"id":"CVE-2020-6096","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-08","epss":0.05354,"percentile":0.92432}],"urls":["https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPYXTDOOB4PQGTYAMZAZNJIB3FF6YQXI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/URXOIA2LDUKHQXK4BE55BQBRI6ZZG3Y6/","https://security.gentoo.org/glsa/202101-20","https://sourceware.org/bugzilla/show_bug.cgi?id=25620","https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1019"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-6096","description":"An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data."}]},{"artifact":{"id":"71315b6fa75a7166","cpes":["cpe:2.3:a:libc6:libc6:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-6096","versionConstraint":"< 2.27-3ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-6096","fix":{"state":"fixed","versions":["2.27-3ubuntu1.5"],"available":[{"date":"2022-03-01","kind":"advisory","version":"2.27-3ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-08","epss":0.05354,"percentile":0.92432}],"risk":1.6062,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-6096"},"relatedVulnerabilities":[{"id":"CVE-2020-6096","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-08","epss":0.05354,"percentile":0.92432}],"urls":["https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPYXTDOOB4PQGTYAMZAZNJIB3FF6YQXI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/URXOIA2LDUKHQXK4BE55BQBRI6ZZG3Y6/","https://security.gentoo.org/glsa/202101-20","https://sourceware.org/bugzilla/show_bug.cgi?id=25620","https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1019"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-6096","description":"An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data."}]},{"artifact":{"id":"62a0389fd254614a","cpes":["cpe:2.3:a:locales:locales:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.27-3ubuntu1?arch=all&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-6096","versionConstraint":"< 2.27-3ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-6096","fix":{"state":"fixed","versions":["2.27-3ubuntu1.5"],"available":[{"date":"2022-03-01","kind":"advisory","version":"2.27-3ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-08","epss":0.05354,"percentile":0.92432}],"risk":1.6062,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-6096"},"relatedVulnerabilities":[{"id":"CVE-2020-6096","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-08","epss":0.05354,"percentile":0.92432}],"urls":["https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPYXTDOOB4PQGTYAMZAZNJIB3FF6YQXI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/URXOIA2LDUKHQXK4BE55BQBRI6ZZG3Y6/","https://security.gentoo.org/glsa/202101-20","https://sourceware.org/bugzilla/show_bug.cgi?id=25620","https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1019"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-6096","description":"An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data."}]},{"artifact":{"id":"6c475aa8af85f1cd","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-6096","versionConstraint":"< 2.27-3ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-6096","fix":{"state":"fixed","versions":["2.27-3ubuntu1.5"],"available":[{"date":"2022-03-01","kind":"advisory","version":"2.27-3ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-08","epss":0.05354,"percentile":0.92432}],"risk":1.6062,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-6096"},"relatedVulnerabilities":[{"id":"CVE-2020-6096","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-08","epss":0.05354,"percentile":0.92432}],"urls":["https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPYXTDOOB4PQGTYAMZAZNJIB3FF6YQXI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/URXOIA2LDUKHQXK4BE55BQBRI6ZZG3Y6/","https://security.gentoo.org/glsa/202101-20","https://sourceware.org/bugzilla/show_bug.cgi?id=25620","https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1019"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-6096","description":"An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data."}]},{"artifact":{"id":"48029af1158e15bb","cpes":["cpe:2.3:a:libjpeg-turbo8:libjpeg-turbo8:1.5.2-0ubuntu5.18.04.1:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg-turbo8:libjpeg_turbo8:1.5.2-0ubuntu5.18.04.1:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg_turbo8:libjpeg-turbo8:1.5.2-0ubuntu5.18.04.1:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg_turbo8:libjpeg_turbo8:1.5.2-0ubuntu5.18.04.1:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg:libjpeg-turbo8:1.5.2-0ubuntu5.18.04.1:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg:libjpeg_turbo8:1.5.2-0ubuntu5.18.04.1:*:*:*:*:*:*:*"],"name":"libjpeg-turbo8","purl":"pkg:deb/ubuntu/libjpeg-turbo8@1.5.2-0ubuntu5.18.04.1?arch=amd64&distro=ubuntu-18.04&upstream=libjpeg-turbo","type":"deb","version":"1.5.2-0ubuntu5.18.04.1","language":"","licenses":["sha256:193468d9eb043a180f6f9e3386f7205104908dcb8525ad39c8236990dfd452ef"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjpeg-turbo8/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libjpeg-turbo8/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjpeg-turbo8:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libjpeg-turbo8:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libjpeg-turbo"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.5.2-0ubuntu5.18.04.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-13790","versionConstraint":"< 1.5.2-0ubuntu5.18.04.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"libjpeg-turbo","version":"1.5.2-0ubuntu5.18.04.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-13790","fix":{"state":"fixed","versions":["1.5.2-0ubuntu5.18.04.4"],"available":[{"date":"2020-06-09","kind":"advisory","version":"1.5.2-0ubuntu5.18.04.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-13790","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-13790","date":"2026-10-08","epss":0.03205,"percentile":0.87777}],"risk":1.6025,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-13790"},"relatedVulnerabilities":[{"id":"CVE-2020-13790","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-13790","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-13790","date":"2026-10-08","epss":0.03205,"percentile":0.87777}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00031.html","http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00062.html","https://github.com/libjpeg-turbo/libjpeg-turbo/commit/3de15e0c344d11d4b90f4a47136467053eb2d09a","https://github.com/libjpeg-turbo/libjpeg-turbo/issues/433","https://lists.debian.org/debian-lts-announce/2020/07/msg00033.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P4D6KNUY7YANSPH7SVQ44PJKSABFKAUB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U6563YHSVZK24MPJXGJVK3CQG7JVWZGK/","https://security.gentoo.org/glsa/202010-03","https://usn.ubuntu.com/4386-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-13790","description":"libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.15+10-0ubuntu0.18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21426","versionConstraint":"< 11.0.15+10-0ubuntu0.18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21426","fix":{"state":"fixed","versions":["11.0.15+10-0ubuntu0.18.04.1"],"available":[{"date":"2022-04-26","kind":"advisory","version":"11.0.15+10-0ubuntu0.18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2022-21426","date":"2026-10-08","epss":0.03203,"percentile":0.87769}],"risk":1.6015000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21426"},"relatedVulnerabilities":[{"id":"CVE-2022-21426","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-21426","date":"2026-10-08","epss":0.03203,"percentile":0.87769}],"urls":["https://lists.debian.org/debian-lts-announce/2022/05/msg00017.html","https://security.netapp.com/advisory/ntap-20220429-0006/","https://www.debian.org/security/2022/dsa-5128","https://www.debian.org/security/2022/dsa-5131","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21426","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-4189","versionConstraint":"< 2.7.17-1~18.04ubuntu1.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-4189","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.7"],"available":[{"date":"2022-03-28","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-4189","date":"2026-10-08","epss":0.03196,"percentile":0.87739}],"risk":1.598,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-4189"},"relatedVulnerabilities":[{"id":"CVE-2021-4189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-4189","date":"2026-10-08","epss":0.03196,"percentile":0.87739}],"urls":["https://access.redhat.com/security/cve/CVE-2021-4189","https://bugs.python.org/issue43285","https://bugzilla.redhat.com/show_bug.cgi?id=2036020","https://github.com/python/cpython/commit/0ab152c6b5d95caa2dc1a30fa96e10258b5f188e","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://python-security.readthedocs.io/vuln/ftplib-pasv.html","https://security-tracker.debian.org/tracker/CVE-2021-4189","https://security.netapp.com/advisory/ntap-20221104-0004/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-4189","description":"A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-4189","versionConstraint":"< 2.7.17-1~18.04ubuntu1.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-4189","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.7"],"available":[{"date":"2022-03-28","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-4189","date":"2026-10-08","epss":0.03196,"percentile":0.87739}],"risk":1.598,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-4189"},"relatedVulnerabilities":[{"id":"CVE-2021-4189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-4189","date":"2026-10-08","epss":0.03196,"percentile":0.87739}],"urls":["https://access.redhat.com/security/cve/CVE-2021-4189","https://bugs.python.org/issue43285","https://bugzilla.redhat.com/show_bug.cgi?id=2036020","https://github.com/python/cpython/commit/0ab152c6b5d95caa2dc1a30fa96e10258b5f188e","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://python-security.readthedocs.io/vuln/ftplib-pasv.html","https://security-tracker.debian.org/tracker/CVE-2021-4189","https://security.netapp.com/advisory/ntap-20221104-0004/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-4189","description":"A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-4189","versionConstraint":"< 2.7.17-1~18.04ubuntu1.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-4189","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.7"],"available":[{"date":"2022-03-28","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-4189","date":"2026-10-08","epss":0.03196,"percentile":0.87739}],"risk":1.598,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-4189"},"relatedVulnerabilities":[{"id":"CVE-2021-4189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-4189","date":"2026-10-08","epss":0.03196,"percentile":0.87739}],"urls":["https://access.redhat.com/security/cve/CVE-2021-4189","https://bugs.python.org/issue43285","https://bugzilla.redhat.com/show_bug.cgi?id=2036020","https://github.com/python/cpython/commit/0ab152c6b5d95caa2dc1a30fa96e10258b5f188e","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://python-security.readthedocs.io/vuln/ftplib-pasv.html","https://security-tracker.debian.org/tracker/CVE-2021-4189","https://security.netapp.com/advisory/ntap-20221104-0004/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-4189","description":"A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-4189","versionConstraint":"< 2.7.17-1~18.04ubuntu1.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-4189","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.7"],"available":[{"date":"2022-03-28","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-4189","date":"2026-10-08","epss":0.03196,"percentile":0.87739}],"risk":1.598,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-4189"},"relatedVulnerabilities":[{"id":"CVE-2021-4189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-4189","date":"2026-10-08","epss":0.03196,"percentile":0.87739}],"urls":["https://access.redhat.com/security/cve/CVE-2021-4189","https://bugs.python.org/issue43285","https://bugzilla.redhat.com/show_bug.cgi?id=2036020","https://github.com/python/cpython/commit/0ab152c6b5d95caa2dc1a30fa96e10258b5f188e","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://python-security.readthedocs.io/vuln/ftplib-pasv.html","https://security-tracker.debian.org/tracker/CVE-2021-4189","https://security.netapp.com/advisory/ntap-20221104-0004/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-4189","description":"A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.9+11-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14803","versionConstraint":"< 11.0.9+11-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14803","fix":{"state":"fixed","versions":["11.0.9+11-0ubuntu1~18.04.1"],"available":[{"date":"2020-10-27","kind":"advisory","version":"11.0.9+11-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14803","date":"2026-10-08","epss":0.03186,"percentile":0.87698}],"risk":1.593,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14803"},"relatedVulnerabilities":[{"id":"CVE-2020-14803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14803","date":"2026-10-08","epss":0.03186,"percentile":0.87698}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://lists.debian.org/debian-lts-announce/2020/10/msg00031.html","https://security.gentoo.org/glsa/202101-19","https://security.netapp.com/advisory/ntap-20201023-0004/","https://www.debian.org/security/2020/dsa-4779","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14803","description":"Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 11.0.8 and 15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"f93d61afc5c3c559","cpes":["cpe:2.3:a:org.springframework.security:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-security-web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_security_web:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:security:5.0.7.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:security:5.0.7.RELEASE:*:*:*:*:*:*:*"],"name":"spring-security-web","purl":"pkg:maven/org.springframework.security/spring-security-web@5.0.7.RELEASE","type":"java-archive","version":"5.0.7.RELEASE","language":"java","licenses":[],"metadata":{"pomGroupID":"org.springframework.security","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-security-web-5.0.7.RELEASE.jar","manifestName":"","pomArtifactID":"spring-security-web","archiveDigests":[{"value":"0bab3ed579d4550bb5cc40b0a7fddd0106db7c66","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-security-web-5.0.7.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.7.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c4q5-6c82-3qpw","versionConstraint":">=5.0.0,<5.7.13 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework.security:spring-security-web","version":"5.0.7.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c4q5-6c82-3qpw","fix":{"state":"fixed","versions":["5.7.13"],"available":[{"date":"2024-10-29","kind":"first-observed","version":"5.7.13"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":9.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-38821","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-38821","date":"2026-10-08","epss":0.01741,"percentile":0.77052}],"risk":1.5843099999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-38821","https://spring.io/security/cve-2024-38821","https://github.com/spring-projects/spring-security/commit/0e257b56ce35402558a260ffa6b368982f9a7934","https://github.com/spring-projects/spring-security/commit/4ce7cde15599c0447163fd46bac616e03318bf5b","https://security.netapp.com/advisory/ntap-20250124-0006","https://github.com/spring-projects/spring-security/commit/b4f27777556c157ec5689c0769322c90be984514"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c4q5-6c82-3qpw","description":"Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications"},"relatedVulnerabilities":[{"id":"CVE-2024-38821","cvss":[{"type":"Secondary","source":"security@vmware.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-38821","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-38821","date":"2026-10-08","epss":0.01741,"percentile":0.77052}],"urls":["https://spring.io/security/cve-2024-38821","https://security.netapp.com/advisory/ntap-20250124-0006/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-38821","description":"Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances.\n\nFor this to impact an application, all of the following must be true:\n\n  *  It must be a WebFlux application\n  *  It must be using Spring's static resources support\n  *  It must have a non-permitAll authorization rule applied to the static resources support"}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.5+10-0ubuntu1.1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-2894","versionConstraint":"< 11.0.5+10-0ubuntu1.1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-2894","fix":{"state":"fixed","versions":["11.0.5+10-0ubuntu1.1~18.04"],"available":[{"date":"2019-12-17","kind":"advisory","version":"11.0.5+10-0ubuntu1.1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2019-2894","date":"2026-10-08","epss":0.03159,"percentile":0.87595}],"risk":1.5795,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-2894"},"relatedVulnerabilities":[{"id":"CVE-2019-2894","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-2894","date":"2026-10-08","epss":0.03159,"percentile":0.87595}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.html","http://www.openwall.com/lists/oss-security/2019/10/02/2","http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://kc.mcafee.com/corporate/index?page=content&id=SB10315","https://lists.debian.org/debian-lts-announce/2019/12/msg00005.html","https://minerva.crocs.fi.muni.cz/","https://seclists.org/bugtraq/2019/Oct/27","https://seclists.org/bugtraq/2019/Oct/31","https://security.netapp.com/advisory/ntap-20191017-0001/","https://usn.ubuntu.com/4223-1/","https://www.debian.org/security/2019/dsa-4546","https://www.debian.org/security/2019/dsa-4548"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-2894","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.118"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r29c-68gh-xp6x","versionConstraint":">=8.5.0,<9.0.118 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r29c-68gh-xp6x","fix":{"state":"fixed","versions":["9.0.118"],"available":[{"date":"2026-05-19","kind":"first-observed","version":"9.0.118"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41293","cwe":"CWE-20","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-41293","date":"2026-10-08","epss":0.0168,"percentile":0.76229}],"risk":1.5792000000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-41293","https://lists.apache.org/thread/qwg0q16z7xkb2qrr853wdll5531mvl1r","http://www.openwall.com/lists/oss-security/2026/05/12/13","https://github.com/apache/tomcat/commit/19f17a257797e8d139b33ff9c88d362a273be148","https://github.com/apache/tomcat/commit/1c70480466572c9192ed412ebefcd43fc63137fd","https://github.com/apache/tomcat/commit/2a2476460e823789f530a22207873ea8cd6eff3b","https://github.com/apache/tomcat/commit/3915fd27e6810b14ccd21e3d900bd8faef44d3df","https://github.com/apache/tomcat/commit/57c2b3bfd62792631e1df24cf4237b990a0b36fa","https://github.com/apache/tomcat/commit/c2925554c677da57390f940d856871e18daaacab","https://github.com/apache/tomcat/commit/cf9452443bcbf3b1a4b435ef7d624364f1b65ca3","https://github.com/apache/tomcat/commit/e5cef9618c3f4fd31bd6fb1e83f0f18022280dac","https://github.com/apache/tomcat/commit/f72a6174ab1f0f5a053435f80448b4f6837fe6d7","https://tomcat.apache.org/security-10.html","https://tomcat.apache.org/security-11.html","https://tomcat.apache.org/security-9.html"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r29c-68gh-xp6x","description":"Apache Tomcat - HTTP/2 request headers not validated"},"relatedVulnerabilities":[{"id":"CVE-2026-41293","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41293","cwe":"CWE-20","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-41293","date":"2026-10-08","epss":0.0168,"percentile":0.76229}],"urls":["https://lists.apache.org/thread/qwg0q16z7xkb2qrr853wdll5531mvl1r","http://www.openwall.com/lists/oss-security/2026/05/12/13"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41293","description":"Improper Input Validation vulnerability in Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27.\nOlder, end of support versions may also be affected.\n\nUsers are recommended to upgrade to version [FIXED_VERSION], which fixes the issue."}]},{"artifact":{"id":"0b1c74783f88c915","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.22.0-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-19959","versionConstraint":"< 3.22.0-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-19959","fix":{"state":"fixed","versions":["3.22.0-1ubuntu0.3"],"available":[{"date":"2020-03-10","kind":"advisory","version":"3.22.0-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-19959","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19959","date":"2026-10-08","epss":0.03156,"percentile":0.87584}],"risk":1.5779999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-19959"},"relatedVulnerabilities":[{"id":"CVE-2019-19959","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-19959","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19959","date":"2026-10-08","epss":0.03156,"percentile":0.87584}],"urls":["https://github.com/sqlite/sqlite/commit/1e490c4ca6b43a9cf8637d695907888349f69bec","https://github.com/sqlite/sqlite/commit/d8f2d46cbc9925e034a68aaaf60aad788d9373c1","https://security.netapp.com/advisory/ntap-20200204-0001/","https://usn.ubuntu.com/4298-1/","https://www.oracle.com/security-alerts/cpuapr2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19959","description":"ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wr62-c79q-cv37","versionConstraint":">=8.5.0,<=8.5.100 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wr62-c79q-cv37","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-52520","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-52520","date":"2026-10-08","epss":0.02102,"percentile":0.81149}],"risk":1.5765000000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-52520","https://lists.apache.org/thread/trqq01bbxw6c92zx69kx2mw2qgmfy0o5","https://github.com/apache/tomcat/commit/927d66fbc294cb65242102b817a45fd80834e040","https://github.com/apache/tomcat/commit/a51e4bedccfafd35b7cdd0ee3e22267dee9f90db","https://github.com/apache/tomcat/commit/fc42bbccb9041fafd194fbfdf3eab1d44cb5c45c","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html","http://www.openwall.com/lists/oss-security/2025/07/10/12"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wr62-c79q-cv37","description":"Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits"},"relatedVulnerabilities":[{"id":"CVE-2025-52520","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-52520","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-52520","date":"2026-10-08","epss":0.02102,"percentile":0.81149}],"urls":["https://lists.apache.org/thread/trqq01bbxw6c92zx69kx2mw2qgmfy0o5","http://www.openwall.com/lists/oss-security/2025/07/10/12","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-52520","description":"For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions \nmay also be affected.\n\n\nUsers are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue."}]},{"artifact":{"id":"3571b4891e14d0b5","cpes":["cpe:2.3:a:libidn2-0:libidn2-0:2.0.4-1.1build2:*:*:*:*:*:*:*","cpe:2.3:a:libidn2-0:libidn2_0:2.0.4-1.1build2:*:*:*:*:*:*:*","cpe:2.3:a:libidn2_0:libidn2-0:2.0.4-1.1build2:*:*:*:*:*:*:*","cpe:2.3:a:libidn2_0:libidn2_0:2.0.4-1.1build2:*:*:*:*:*:*:*","cpe:2.3:a:libidn2:libidn2-0:2.0.4-1.1build2:*:*:*:*:*:*:*","cpe:2.3:a:libidn2:libidn2_0:2.0.4-1.1build2:*:*:*:*:*:*:*"],"name":"libidn2-0","purl":"pkg:deb/ubuntu/libidn2-0@2.0.4-1.1build2?arch=amd64&distro=ubuntu-18.04&upstream=libidn2","type":"deb","version":"2.0.4-1.1build2","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-3","LGPL-3+","Unicode"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libidn2-0/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libidn2-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libidn2-0:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libidn2-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libidn2"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.0.4-1.1ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-12290","versionConstraint":"< 2.0.4-1.1ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"libidn2","version":"2.0.4-1.1build2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-12290","fix":{"state":"fixed","versions":["2.0.4-1.1ubuntu0.2"],"available":[{"date":"2019-10-29","kind":"advisory","version":"2.0.4-1.1ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-12290","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-12290","date":"2026-10-08","epss":0.03106,"percentile":0.87386}],"risk":1.553,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-12290"},"relatedVulnerabilities":[{"id":"CVE-2019-12290","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12290","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-12290","date":"2026-10-08","epss":0.03106,"percentile":0.87386}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00008.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00009.html","https://gitlab.com/libidn/libidn2/commit/241e8f486134793cb0f4a5b0e5817a97883401f5","https://gitlab.com/libidn/libidn2/commit/614117ef6e4c60e1950d742e3edf0a0ef8d389de","https://gitlab.com/libidn/libidn2/merge_requests/71","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFT76Y7OSGPZV3EBEHD6ISVUM3DLARM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KXDKYWFV6N2HHVSE67FFDM7G3FEL2ZNE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ONG3GJRRJO35COPGVJXXSZLU4J5Y42AT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSI4TI2JTQWQ3YEUX5X36GTVGKO4QKZ5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U6ZXL2RDNQRAHCMKWPOMJFKYJ344X4HL/","https://security.gentoo.org/glsa/202003-63","https://usn.ubuntu.com/4168-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12290","description":"GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21277","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21277","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21277","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21277","date":"2026-10-08","epss":0.03091,"percentile":0.87335}],"risk":1.5455,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21277"},"relatedVulnerabilities":[{"id":"CVE-2022-21277","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21277","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21277","date":"2026-10-08","epss":0.03091,"percentile":0.87335}],"urls":["https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21277","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"ec4e0702f60fa53e","cpes":["cpe:2.3:a:apache:tomcat-embed-core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:8.5.32:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.32","type":"java-archive","version":"8.5.32","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"6bc6896200146010cc4666bdc6b9b0cbb453ee22","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/tomcat-embed-core-8.5.32.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-25xr-qj8w-c4vf","versionConstraint":">=8.5.0,<=8.5.100 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"8.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-25xr-qj8w-c4vf","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53506","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-53506","date":"2026-10-08","epss":0.02035,"percentile":0.80491}],"risk":1.52625,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-53506","https://lists.apache.org/thread/p09775q0rd185m6zz98krg0fp45j8kr0","https://github.com/apache/tomcat/commit/2aa6261276ebe50b99276953591e3a2be7898bdb","https://github.com/apache/tomcat/commit/434772930f362145516dd60681134e7f0cf8115b","https://github.com/apache/tomcat/commit/be8f330f83ceddaf3baeed57522e571572b6b99b","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html","http://www.openwall.com/lists/oss-security/2025/07/10/13"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-25xr-qj8w-c4vf","description":"Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams"},"relatedVulnerabilities":[{"id":"CVE-2025-53506","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53506","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-53506","date":"2026-10-08","epss":0.02035,"percentile":0.80491}],"urls":["https://lists.apache.org/thread/p09775q0rd185m6zz98krg0fp45j8kr0","http://www.openwall.com/lists/oss-security/2025/07/10/13","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53506","description":"Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 through 8.5.100. Other EOL versions may also be affected.\n\n\nUsers are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue."}]},{"artifact":{"id":"d6a5b2a85e3fbcb7","cpes":["cpe:2.3:a:libseccomp2:libseccomp2:2.3.1-2.1ubuntu4:*:*:*:*:*:*:*"],"name":"libseccomp2","purl":"pkg:deb/ubuntu/libseccomp2@2.3.1-2.1ubuntu4?arch=amd64&distro=ubuntu-18.04&upstream=libseccomp","type":"deb","version":"2.3.1-2.1ubuntu4","language":"","licenses":["sha256:739b879afbd6a2c602ed4e9be2dee2e60e1c1bfa0eb8a1acdb178f2ff8fd5e6f"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libseccomp2/copyright","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/usr/share/doc/libseccomp2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libseccomp2:amd64.md5sums","layerID":"sha256:f8e6b96dc7db682eb22560429bed3aa1c07efcb14d8739f433a37c38e99eb432","accessPath":"/var/lib/dpkg/info/libseccomp2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libseccomp"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.1-0ubuntu0.18.04.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9893","versionConstraint":"< 2.4.1-0ubuntu0.18.04.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"libseccomp","version":"2.3.1-2.1ubuntu4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9893","fix":{"state":"fixed","versions":["2.4.1-0ubuntu0.18.04.2"],"available":[{"date":"2019-05-30","kind":"advisory","version":"2.4.1-0ubuntu0.18.04.2"}]},"cvss":[],"epss":[{"cve":"CVE-2019-9893","date":"2026-10-08","epss":0.03041,"percentile":0.8713}],"risk":1.5205,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9893"},"relatedVulnerabilities":[{"id":"CVE-2019-9893","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-9893","date":"2026-10-08","epss":0.03041,"percentile":0.8713}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00022.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00027.html","https://access.redhat.com/errata/RHSA-2019:3624","https://github.com/seccomp/libseccomp/issues/139","https://seclists.org/oss-sec/2019/q1/179","https://security.gentoo.org/glsa/201904-18","https://usn.ubuntu.com/4001-1/","https://usn.ubuntu.com/4001-2/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9893","description":"libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing seccomp filters and potential privilege escalations."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.8+10-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14556","versionConstraint":"< 11.0.8+10-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14556","fix":{"state":"fixed","versions":["11.0.8+10-0ubuntu1~18.04.1"],"available":[{"date":"2020-07-23","kind":"advisory","version":"11.0.8+10-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14556","date":"2026-10-08","epss":0.03022,"percentile":0.87059}],"risk":1.5110000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14556"},"relatedVulnerabilities":[{"id":"CVE-2020-14556","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14556","date":"2026-10-08","epss":0.03022,"percentile":0.87059}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html","http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CFJPOYF3CWYEPCDOAOCNFJTQIKKWPHW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFZ36XIW5ENQAW6BB7WHRFFTTJX7KGMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/","https://security.gentoo.org/glsa/202008-24","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200717-0005/","https://usn.ubuntu.com/4433-1/","https://usn.ubuntu.com/4453-1/","https://www.debian.org/security/2020/dsa-4734","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14556","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data as well as unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-22947","versionConstraint":"< 7.58.0-2ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22947","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.15"],"available":[{"date":"2021-09-15","kind":"advisory","version":"7.58.0-2ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22947","cwe":"CWE-310","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22947","cwe":"CWE-345","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22947","date":"2026-10-08","epss":0.03009,"percentile":0.87008}],"risk":1.5045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22947"},"relatedVulnerabilities":[{"id":"CVE-2021-22947","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22947","cwe":"CWE-310","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22947","cwe":"CWE-345","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22947","date":"2026-10-08","epss":0.03009,"percentile":0.87008}],"urls":["http://seclists.org/fulldisclosure/2022/Mar/29","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://hackerone.com/reports/1334763","https://lists.debian.org/debian-lts-announce/2021/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20211029-0003/","https://support.apple.com/kb/HT213183","https://www.debian.org/security/2022/dsa-5197","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22947","description":"When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-22947","versionConstraint":"< 7.58.0-2ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22947","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.15"],"available":[{"date":"2021-09-15","kind":"advisory","version":"7.58.0-2ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22947","cwe":"CWE-310","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22947","cwe":"CWE-345","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22947","date":"2026-10-08","epss":0.03009,"percentile":0.87008}],"risk":1.5045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22947"},"relatedVulnerabilities":[{"id":"CVE-2021-22947","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22947","cwe":"CWE-310","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22947","cwe":"CWE-345","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22947","date":"2026-10-08","epss":0.03009,"percentile":0.87008}],"urls":["http://seclists.org/fulldisclosure/2022/Mar/29","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://hackerone.com/reports/1334763","https://lists.debian.org/debian-lts-announce/2021/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20211029-0003/","https://support.apple.com/kb/HT213183","https://www.debian.org/security/2022/dsa-5197","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22947","description":"When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server."}]},{"artifact":{"id":"a5ac54476e47c1ea","cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.35-2ubuntu2.1:*:*:*:*:*:*:*"],"name":"libnss3","purl":"pkg:deb/ubuntu/libnss3@2%3A3.35-2ubuntu2.1?arch=amd64&distro=ubuntu-18.04&upstream=nss","type":"deb","version":"2:3.35-2ubuntu2.1","language":"","licenses":["HPND","HPND-sell-variant","MIT","MPL-2.0","Zlib","blessing"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss3/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libnss3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nss"}]},"matchDetails":[{"fix":{"suggestedVersion":"2:3.35-2ubuntu2.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-11745","versionConstraint":"< 2:3.35-2ubuntu2.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nss","version":"2:3.35-2ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-11745","fix":{"state":"fixed","versions":["2:3.35-2ubuntu2.5"],"available":[{"date":"2019-11-27","kind":"advisory","version":"2:3.35-2ubuntu2.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-11745","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-11745","date":"2026-10-08","epss":0.02994,"percentile":0.86944}],"risk":1.497,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-11745"},"relatedVulnerabilities":[{"id":"CVE-2019-11745","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-11745","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-11745","date":"2026-10-08","epss":0.02994,"percentile":0.86944}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00000.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00001.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00006.html","https://access.redhat.com/errata/RHSA-2020:0243","https://access.redhat.com/errata/RHSA-2020:0466","https://bugzilla.mozilla.org/show_bug.cgi?id=1586176","https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdf","https://lists.debian.org/debian-lts-announce/2020/09/msg00029.html","https://security.gentoo.org/glsa/202003-02","https://security.gentoo.org/glsa/202003-10","https://security.gentoo.org/glsa/202003-37","https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04","https://usn.ubuntu.com/4241-1/","https://usn.ubuntu.com/4335-1/","https://www.mozilla.org/security/advisories/mfsa2019-36/","https://www.mozilla.org/security/advisories/mfsa2019-37/","https://www.mozilla.org/security/advisories/mfsa2019-38/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-11745","description":"When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71."}]},{"artifact":{"id":"4c81298b0e59fc02","cpes":["cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_minimal:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-minimal","purl":"pkg:deb/ubuntu/libpython2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-20907","versionConstraint":"< 2.7.17-1~18.04ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-20907","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.1"],"available":[{"date":"2020-07-22","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20907","date":"2026-10-08","epss":0.02985,"percentile":0.86903}],"risk":1.4925000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-20907"},"relatedVulnerabilities":[{"id":"CVE-2019-20907","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20907","date":"2026-10-08","epss":0.02985,"percentile":0.86903}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00052.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00056.html","https://bugs.python.org/issue39017","https://github.com/python/cpython/pull/21454","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAXHCY4V3LPAAJOBCJ26ISZ4NUXQXTUZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDKKRXLNVXRF6VGERZSR3OMQR5D5QI6I/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOGKLGTXZLHQQFBVCAPSUDA6DOOJFNRY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSL3XWVDMSMKO23HR74AJQ6VEM3C2NTS/","https://security.gentoo.org/glsa/202008-01","https://security.netapp.com/advisory/ntap-20200731-0002/","https://usn.ubuntu.com/4428-1/","https://www.oracle.com/security-alerts/cpujan2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-20907","description":"In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation."}]},{"artifact":{"id":"87130d096d595f69","cpes":["cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7-stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7_stdlib:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7-stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libpython2.7:libpython2.7_stdlib:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libpython2.7-stdlib","purl":"pkg:deb/ubuntu/libpython2.7-stdlib@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/libpython2.7-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/libpython2.7-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-20907","versionConstraint":"< 2.7.17-1~18.04ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-20907","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.1"],"available":[{"date":"2020-07-22","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20907","date":"2026-10-08","epss":0.02985,"percentile":0.86903}],"risk":1.4925000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-20907"},"relatedVulnerabilities":[{"id":"CVE-2019-20907","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20907","date":"2026-10-08","epss":0.02985,"percentile":0.86903}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00052.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00056.html","https://bugs.python.org/issue39017","https://github.com/python/cpython/pull/21454","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAXHCY4V3LPAAJOBCJ26ISZ4NUXQXTUZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDKKRXLNVXRF6VGERZSR3OMQR5D5QI6I/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOGKLGTXZLHQQFBVCAPSUDA6DOOJFNRY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSL3XWVDMSMKO23HR74AJQ6VEM3C2NTS/","https://security.gentoo.org/glsa/202008-01","https://security.netapp.com/advisory/ntap-20200731-0002/","https://usn.ubuntu.com/4428-1/","https://www.oracle.com/security-alerts/cpujan2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-20907","description":"In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation."}]},{"artifact":{"id":"f2e5c857d07dae7d","cpes":["cpe:2.3:a:python2.7:python2.7:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7","purl":"pkg:deb/ubuntu/python2.7@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.list"},{"path":"/var/lib/dpkg/info/python2.7.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.postinst"},{"path":"/var/lib/dpkg/info/python2.7.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-20907","versionConstraint":"< 2.7.17-1~18.04ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-20907","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.1"],"available":[{"date":"2020-07-22","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20907","date":"2026-10-08","epss":0.02985,"percentile":0.86903}],"risk":1.4925000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-20907"},"relatedVulnerabilities":[{"id":"CVE-2019-20907","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20907","date":"2026-10-08","epss":0.02985,"percentile":0.86903}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00052.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00056.html","https://bugs.python.org/issue39017","https://github.com/python/cpython/pull/21454","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAXHCY4V3LPAAJOBCJ26ISZ4NUXQXTUZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDKKRXLNVXRF6VGERZSR3OMQR5D5QI6I/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOGKLGTXZLHQQFBVCAPSUDA6DOOJFNRY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSL3XWVDMSMKO23HR74AJQ6VEM3C2NTS/","https://security.gentoo.org/glsa/202008-01","https://security.netapp.com/advisory/ntap-20200731-0002/","https://usn.ubuntu.com/4428-1/","https://www.oracle.com/security-alerts/cpujan2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-20907","description":"In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation."}]},{"artifact":{"id":"1e69d26dda567697","cpes":["cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7-minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7_minimal:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7-minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:python2.7:python2.7_minimal:2.7.15\\~rc1-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"python2.7-minimal","purl":"pkg:deb/ubuntu/python2.7-minimal@2.7.15~rc1-1ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=python2.7","type":"deb","version":"2.7.15~rc1-1ubuntu0.1","language":"","licenses":["sha256:47fa580bb89cf86920b4deff31f21f629d982890d2e909ce0baaee94962ff1ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python2.7-minimal/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/python2.7-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python2.7-minimal.list","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.list"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.postrm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.postrm"},{"path":"/var/lib/dpkg/info/python2.7-minimal.preinst","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.preinst"},{"path":"/var/lib/dpkg/info/python2.7-minimal.prerm","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/python2.7-minimal.prerm"}],"upstreams":[{"name":"python2.7"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.17-1~18.04ubuntu1.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-20907","versionConstraint":"< 2.7.17-1~18.04ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python2.7","version":"2.7.15~rc1-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-20907","fix":{"state":"fixed","versions":["2.7.17-1~18.04ubuntu1.1"],"available":[{"date":"2020-07-22","kind":"advisory","version":"2.7.17-1~18.04ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20907","date":"2026-10-08","epss":0.02985,"percentile":0.86903}],"risk":1.4925000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-20907"},"relatedVulnerabilities":[{"id":"CVE-2019-20907","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20907","date":"2026-10-08","epss":0.02985,"percentile":0.86903}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00052.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00056.html","https://bugs.python.org/issue39017","https://github.com/python/cpython/pull/21454","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAXHCY4V3LPAAJOBCJ26ISZ4NUXQXTUZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDKKRXLNVXRF6VGERZSR3OMQR5D5QI6I/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOGKLGTXZLHQQFBVCAPSUDA6DOOJFNRY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSL3XWVDMSMKO23HR74AJQ6VEM3C2NTS/","https://security.gentoo.org/glsa/202008-01","https://security.netapp.com/advisory/ntap-20200731-0002/","https://usn.ubuntu.com/4428-1/","https://www.oracle.com/security-alerts/cpujan2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-20907","description":"In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation."}]},{"artifact":{"id":"15d5eeeb3031fa09","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:10.0.2\\+13-1ubuntu0.18.04.4:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@10.0.2%2B13-1ubuntu0.18.04.4?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"10.0.2+13-1ubuntu0.18.04.4","language":"","licenses":["sha256:64cde4476532f042c28dc301a6af2cb3c57fabab03cf6fde08ca93de3063ea64"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.7+10-2ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-2781","versionConstraint":"< 11.0.7+10-2ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"10.0.2+13-1ubuntu0.18.04.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-2781","fix":{"state":"fixed","versions":["11.0.7+10-2ubuntu2~18.04"],"available":[{"date":"2020-04-22","kind":"advisory","version":"11.0.7+10-2ubuntu2~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2020-2781","date":"2026-10-08","epss":0.04948,"percentile":0.91941}],"risk":1.4844,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-2781"},"relatedVulnerabilities":[{"id":"CVE-2020-2781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-2781","date":"2026-10-08","epss":0.04948,"percentile":0.91941}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00000.html","http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00023.html","http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00048.html","https://kc.mcafee.com/corporate/index?page=content&id=SB10318","https://lists.debian.org/debian-lts-announce/2020/04/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CKAV6KFFAEANXAN73AFTGU7Z6YNRWCXQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7VHC4EW36KZEIDQ56RPCWBZCQELFFKN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NYHHHZRHXCBGRHGE5UP7UEB4IZ2QX536/","https://security.gentoo.org/glsa/202006-22","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200416-0004/","https://usn.ubuntu.com/4337-1/","https://www.debian.org/security/2020/dsa-4662","https://www.debian.org/security/2020/dsa-4668","https://www.oracle.com/security-alerts/cpuapr2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-2781","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"dbc19132357243c6","cpes":["cpe:2.3:a:org.springframework:spring-beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-beans:spring-beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-beans:spring_beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_beans:spring-beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_beans:spring_beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-beans:5.0.8.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_beans:5.0.8.RELEASE:*:*:*:*:*:*:*"],"name":"spring-beans","purl":"pkg:maven/org.springframework/spring-beans@5.0.8.RELEASE","type":"java-archive","version":"5.0.8.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-beans-5.0.8.RELEASE.jar","manifestName":"","pomArtifactID":"spring-beans","archiveDigests":[{"value":"5fc965d3e7f5515099244857a8ae9e2a208c169b","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.2.1-exec.jar","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/app/hydra2/lib/core-2.2.1-exec.jar:BOOT-INF/lib/spring-beans-5.0.8.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.2.22.RELEASE"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hh26-6xwr-ggv7","versionConstraint":"<=5.2.21.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-beans","version":"5.0.8.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hh26-6xwr-ggv7","fix":{"state":"fixed","versions":["5.2.22.RELEASE"],"available":[{"date":"2024-02-03","kind":"first-observed","version":"5.2.22.RELEASE"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22970","cwe":"CWE-770","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22970","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22970","date":"2026-10-08","epss":0.01962,"percentile":0.79727}],"risk":1.4714999999999998,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22970","https://tanzu.vmware.com/security/cve-2022-22970","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/spring-projects/spring-framework/commit/83186b689f11f5e6efe7ccc08fdeb92f66fcd583","https://github.com/spring-projects/spring-framework/commit/50177b1ad3485bd44239b1756f6c14607476fcf2","https://security.netapp.com/advisory/ntap-20220616-0006"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hh26-6xwr-ggv7","description":"Denial of service in Spring Framework"},"relatedVulnerabilities":[{"id":"CVE-2022-22970","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:N/I:N/A:P","metrics":{"baseScore":3.5,"impactScore":2.9,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22970","cwe":"CWE-770","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22970","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22970","date":"2026-10-08","epss":0.01962,"percentile":0.79727}],"urls":["https://security.netapp.com/advisory/ntap-20220616-0006/","https://tanzu.vmware.com/security/cve-2022-22970","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22970","description":"In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object."}]},{"artifact":{"id":"6adc12220ad05a42","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.18"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-27782","versionConstraint":"< 7.58.0-2ubuntu3.18 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-27782","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.18"],"available":[{"date":"2022-05-11","kind":"advisory","version":"7.58.0-2ubuntu3.18"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-27782","cwe":"CWE-840","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-27782","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-27782","date":"2026-10-08","epss":0.0293,"percentile":0.86676}],"risk":1.465,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-27782"},"relatedVulnerabilities":[{"id":"CVE-2022-27782","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27782","cwe":"CWE-840","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-27782","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-27782","date":"2026-10-08","epss":0.0293,"percentile":0.86676}],"urls":["http://www.openwall.com/lists/oss-security/2023/03/20/6","https://hackerone.com/reports/1555796","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20220609-0009/","https://www.debian.org/security/2022/dsa-5197"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27782","description":"libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily."}]},{"artifact":{"id":"d8a259f408e474ab","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.5:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.5?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.5","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6eb3e6a35efd7645aaadb4df808f2db404755ada7d344b5dd6ceefa837664598","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:e53dfbd4af938a897f5bd4e7e551592c080f3b297898d7b278e08b16a3b0ee53","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.18"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-27782","versionConstraint":"< 7.58.0-2ubuntu3.18 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-27782","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.18"],"available":[{"date":"2022-05-11","kind":"advisory","version":"7.58.0-2ubuntu3.18"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-27782","cwe":"CWE-840","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-27782","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-27782","date":"2026-10-08","epss":0.0293,"percentile":0.86676}],"risk":1.465,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-27782"},"relatedVulnerabilities":[{"id":"CVE-2022-27782","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27782","cwe":"CWE-840","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-27782","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-27782","date":"2026-10-08","epss":0.0293,"percentile":0.86676}],"urls":["http://www.openwall.com/lists/oss-security/2023/03/20/6","https://hackerone.com/reports/1555796","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20220609-0009/","https://www.debian.org/security/2022/dsa-5197"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27782","description":"libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T19:19:11.319Z","grype_db_version":"2026-10-09T06:32:32.000Z"}