GithubHelp home page GithubHelp logo

explorer-statistics's People

Contributors

dependabot[bot] avatar leej1012 avatar nashmiao avatar xizho10 avatar zzszhou avatar

Watchers

 avatar  avatar  avatar

explorer-statistics's Issues

List of CRIT CVEs for explorer-statistics

Below is a list of CRIT CVEs for explorer-statistics service. Most can be rectified by specifying fixed dep versions in a custom pom.xml file, but unfortunately not org.springframework:spring-web.

Here is the full list.

Total: 10 (CRITICAL: 10)
┌─────────────────────────────────────────────────────────────┬──────────────────┬──────────┬────────┬───────────────────┬────────────────┬────────────────────────────────────────────────────────────┐
│                           Library                           │  Vulnerability   │ Severity │ Status │ Installed Version │ Fixed Version  │                           Title                            │
├─────────────────────────────────────────────────────────────┼──────────────────┼──────────┼────────┼───────────────────┼────────────────┼────────────────────────────────────────────────────────────┤
│ com.github.pagehelper:pagehelper (app.jar)                  │ CVE-2022-28111   │ CRITICAL │ fixed  │ 5.2.1             │ 5.3.1          │ MyBatis PageHelper vulnerable to time-blind SQL injection  │
│                                                             │                  │          │        │                   │                │ via orderBy parameter                                      │
│                                                             │                  │          │        │                   │                │ https://avd.aquasec.com/nvd/cve-2022-28111                 │
├─────────────────────────────────────────────────────────────┼──────────────────┤          │        ├───────────────────┼────────────────┼────────────────────────────────────────────────────────────┤
│ io.springfox:springfox-swagger-ui (app.jar)                 │ CVE-2019-17495   │          │        │ 2.9.2             │ 2.10.0         │ Cross-site scripting in Swagger-UI                         │
│                                                             │                  │          │        │                   │                │ https://avd.aquasec.com/nvd/cve-2019-17495                 │
├─────────────────────────────────────────────────────────────┼──────────────────┤          │        ├───────────────────┼────────────────┼────────────────────────────────────────────────────────────┤
│ org.bouncycastle:bcprov-jdk15on (app.jar)                   │ CVE-2018-1000613 │          │        │ 1.59              │ 1.60           │ bouncycastle: lack of class checking in deserialization of │
│                                                             │                  │          │        │                   │                │ XMSS/XMSS^MT private keys with...                          │
│                                                             │                  │          │        │                   │                │ https://avd.aquasec.com/nvd/cve-2018-1000613               │
├─────────────────────────────────────────────────────────────┼──────────────────┤          │        ├───────────────────┼────────────────┼────────────────────────────────────────────────────────────┤
│ org.springframework.boot:spring-boot (app.jar)              │ CVE-2022-22965   │          │        │ 2.5.1             │ 2.5.12, 2.6.6  │ RCE via Data Binding on JDK 9+                             │
│                                                             │                  │          │        │                   │                │ https://avd.aquasec.com/nvd/cve-2022-22965                 │
├─────────────────────────────────────────────────────────────┼──────────────────┤          │        │                   ├────────────────┼────────────────────────────────────────────────────────────┤
│ org.springframework.boot:spring-boot-actuator-autoconfigure │ CVE-2023-20873   │          │        │                   │ 2.7.11, 3.0.6  │ Security Bypass With Wildcard Pattern Matching on Cloud    │
│ (app.jar)                                                   │                  │          │        │                   │                │ Foundry                                                    │
│                                                             │                  │          │        │                   │                │ https://avd.aquasec.com/nvd/cve-2023-20873                 │
├─────────────────────────────────────────────────────────────┼──────────────────┤          │        ├───────────────────┼────────────────┼────────────────────────────────────────────────────────────┤
│ org.springframework:spring-beans (app.jar)                  │ CVE-2022-22965   │          │        │ 5.3.8             │ 5.2.20, 5.3.18 │ RCE via Data Binding on JDK 9+                             │
│                                                             │                  │          │        │                   │                │ https://avd.aquasec.com/nvd/cve-2022-22965                 │
├─────────────────────────────────────────────────────────────┤                  │          │        │                   │                │                                                            │
│ org.springframework:spring-core (app.jar)                   │                  │          │        │                   │                │                                                            │
│                                                             │                  │          │        │                   │                │                                                            │
├─────────────────────────────────────────────────────────────┼──────────────────┤          │        │                   ├────────────────┼────────────────────────────────────────────────────────────┤
│ org.springframework:spring-web (app.jar)                    │ CVE-2016-1000027 │          │        │                   │ 6.0.0          │ spring: HttpInvokerServiceExporter readRemoteInvocation    │
│                                                             │                  │          │        │                   │                │ method untrusted java deserialization                      │
│                                                             │                  │          │        │                   │                │ https://avd.aquasec.com/nvd/cve-2016-1000027               │
├─────────────────────────────────────────────────────────────┼──────────────────┤          │        │                   ├────────────────┼────────────────────────────────────────────────────────────┤
│ org.springframework:spring-webmvc (app.jar)                 │ CVE-2022-22965   │          │        │                   │ 5.2.20, 5.3.18 │ RCE via Data Binding on JDK 9+                             │
│                                                             │                  │          │        │                   │                │ https://avd.aquasec.com/nvd/cve-2022-22965                 │
├─────────────────────────────────────────────────────────────┼──────────────────┤          │        ├───────────────────┼────────────────┼────────────────────────────────────────────────────────────┤
│ org.yaml:snakeyaml (app.jar)                                │ CVE-2022-1471    │          │        │ 1.28              │ 2.0            │ Constructor Deserialization Remote Code Execution          │
│                                                             │                  │          │        │                   │                │ https://avd.aquasec.com/nvd/cve-2022-1471                  │
└─────────────────────────────────────────────────────────────┴──────────────────┴──────────┴────────┴───────────────────┴────────────────┴────────────────────────────────────────────────────────────┘

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.