Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

107 advisories

Loading
Improper Limitation of a Pathname to a Restricted Directory in Jboss EAP Undertow High
CVE-2018-1048 was published for org.jboss.eap:wildfly-undertow (Maven) May 13, 2022
Path Traversal in Jenkins High
CVE-2018-1000194 was published for org.jenkins-ci.main:jenkins-core (Maven) May 13, 2022
Arbitrary filesystem write access from velocity. High
CVE-2022-24897 was published for org.xwiki.commons:xwiki-commons-velocity (Maven) Apr 28, 2022
kurt-r2c
Path traversal in the OWASP Enterprise Security API High
CVE-2022-23457 was published for org.owasp.esapi:esapi (Maven) Apr 27, 2022
JarLob
Path Traversal in Caucho Resin High
CVE-2021-44138 was published for com.caucho:resin (Maven) Apr 5, 2022
Path traversal in MCMS High
CVE-2021-46037 was published for net.mingsoft:ms-mcms (Maven) Feb 19, 2022
MCMS Arbitrary File Deletion vulnerability High
CVE-2021-46062 was published for net.mingsoft:ms-basic (Maven) Feb 19, 2022
Path Traversal in Crafter CMS Crafter Studio High
CVE-2017-15684 was published for org.craftercms:crafter-studio (Maven) Feb 9, 2022
Upload of file to arbitrary path in Apache Flink High
CVE-2020-17518 was published for org.apache.flink:flink-runtime (Maven) Feb 9, 2022
Path Traversal High
CVE-2020-14366 was published for org.keycloak:keycloak-parent (Maven) Feb 9, 2022
Path Traversal in Jenkins Warnings Next Generation Plugin High
CVE-2022-23107 was published for io.jenkins.plugins:warnings-ng (Maven) Jan 21, 2022
westonsteimel
Path Traversal in com.linecorp.armeria:armeria High
CVE-2021-43795 was published for com.linecorp.armeria:armeria (Maven) Dec 2, 2021
Directory traversal in Eclipse Mojarra High
CVE-2020-6950 was published for org.glassfish:mojarra-parent (Maven) Sep 1, 2021
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in micronaut-core High
CVE-2021-32769 was published for io.micronaut:micronaut-http-server-netty (Maven) Jul 26, 2021
strmik
Path Traversal in the Java Kubernetes Client High
CVE-2020-8570 was published for io.kubernetes:client-java (Maven) Jan 29, 2021
Path Traversal in Apache Flink High
CVE-2020-17519 was published for org.apache.flink:flink-runtime_2.11 (Maven) Jan 6, 2021
stephanmiehe
Directory Traversal in spring-boot-actuator-logview High
CVE-2021-21234 was published for eu.hinsch:spring-boot-actuator-logview (Maven) Jan 5, 2021
st0rmi
Directory traversal attack in Spring Cloud Config High
CVE-2020-5410 was published for org.springframework.cloud:spring-cloud-config-server (Maven) Jun 5, 2020
Path traversal attack on Windows platforms High
CVE-2019-0207 was published for org.apache.tapestry:tapestry-core (Maven) Nov 18, 2019
Path Traversal in DKPro Core High
CVE-2019-11082 was published for de.tudarmstadt.ukp.dkpro.core:de.tudarmstadt.ukp.dkpro.core.api.datasets-asl (Maven) May 29, 2019
Path Traversal in Apache Camel High
CVE-2019-0194 was published for org.apache.camel:camel-core (Maven) May 2, 2019
Improper Limitation of a Pathname ('Path Traversal') in org.apache.jspwiki:jspwiki-war High
CVE-2019-0225 was published for org.apache.jspwiki:jspwiki-war (Maven) Apr 8, 2019
Path Traversal in Hadoop High
CVE-2018-8009 was published for org.apache.hadoop:hadoop-main (Maven) Dec 21, 2018
MarkLee131
Directory Traversal vulnerability in Square Retrofit High
CVE-2018-1000850 was published for com.squareup.retrofit2:retrofit (Maven) Dec 21, 2018
XXL-CONF Path Traversal vulnerability High
CVE-2018-20094 was published for com.xuxueli:xxl-conf-admin (Maven) Dec 19, 2018
ProTip! Advisories are also available from the GraphQL API