Skip to content

[Snyk] Security upgrade io.jsonwebtoken:jjwt from 0.9.1 to 0.12.0 - #33

Open
RoyHarrow wants to merge 1 commit into
developfrom
snyk-fix-e2ead8bc378b0e00b9186cafbc3f4627
Open

[Snyk] Security upgrade io.jsonwebtoken:jjwt from 0.9.1 to 0.12.0#33
RoyHarrow wants to merge 1 commit into
developfrom
snyk-fix-e2ead8bc378b0e00b9186cafbc3f4627

Conversation

@RoyHarrow

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • webgoat-lessons/jwt/pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Score Upgrade
high severity Stack-based Buffer Overflow
SNYK-JAVA-COMFASTERXMLJACKSONCORE-10500754
  721   io.jsonwebtoken:jjwt:
0.9.1 -> 0.12.0
No Known Exploit

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@RoyHarrow

Copy link
Copy Markdown
Owner Author

Logo
Checkmarx One – Scan Summary & Detailsfe3690f0-5d37-47d6-a40d-f30a594ddf84

New Issues (465)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
CRITICAL CVE-2013-7285 Maven-com.thoughtworks.xstream:xstream-1.4.5
detailsRecommended version: 1.4.21
Description: Xstream API versions up to 1.4.6, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands b...
Attack Vector: NETWORK
Attack Complexity: LOW
Exploitable Path: fromXML@...rableComponentsLessonTest.java - ... - canConvert@...on/ReflectionConverter.java

ID: bpaT%2FDwFjWJ7jRsV%2F9yMQ17kJcDr6f8jIrObEu2hhpw%3D
Vulnerable Package
CRITICAL CVE-2016-1000027 Maven-org.springframework:spring-web-5.3.9
detailsRecommended version: 5.3.31-wso2v1
Description: Pivotal Spring Framework (spring, spring-remoting, spring-web, spring-webmvc) versions prior to 6.0.0-M1, suffers from a potential remote code exec...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: cF9X4AMA3oUjxJ4BviEFlL8Kr3%2FeTLPJ%2B2tFelZGD9c%3D
Vulnerable Package
CRITICAL CVE-2016-1000027 Maven-org.springframework:spring-webmvc-5.3.9
detailsRecommended version: 5.3.39-atlassian-3
Description: Pivotal Spring Framework (spring, spring-remoting, spring-web, spring-webmvc) versions prior to 6.0.0-M1, suffers from a potential remote code exec...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Ucc6Ojajc1vWFQTB8OHilbEvMESP7MB6XLqsv7q%2Bfck%3D
Vulnerable Package
CRITICAL CVE-2021-21342 Maven-com.thoughtworks.xstream:xstream-1.4.5
detailsRecommended version: 1.4.21
Description: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processe...
Attack Vector: NETWORK
Attack Complexity: LOW
Exploitable Path: alias@...nerableComponentsLessonTest.java - ... - alias@...houghtworks/xstream/XStream.java

ID: C1bm%2FQ9bWe0iKXfn4dqPfSvtVRqpZfUxpjD95fB3fMo%3D
Vulnerable Package
CRITICAL CVE-2021-21344 Maven-com.thoughtworks.xstream:xstream-1.4.5
detailsRecommended version: 1.4.21
Description: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a ...
Attack Vector: NETWORK
Attack Complexity: LOW
Exploitable Path: alias@...nerableComponentsLessonTest.java - ... - alias@...houghtworks/xstream/XStream.java

ID: gSmLIcK21CgFdxDPCR5pQ2XCqivQ9Xw0%2B4yUauNs9lw%3D
Vulnerable Package
CRITICAL CVE-2021-21345 Maven-com.thoughtworks.xstream:xstream-1.4.5
detailsRecommended version: 1.4.21
Description: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a ...
Attack Vector: NETWORK
Attack Complexity: LOW
Exploitable Path: alias@...nerableComponentsLessonTest.java - ... - alias@...houghtworks/xstream/XStream.java

ID: 25mMUvITENR6WQ3s2hZwYYJZmzpX2A0jbmWH8yDhXAI%3D
Vulnerable Package
CRITICAL CVE-2021-21346 Maven-com.thoughtworks.xstream:xstream-1.4.5
detailsRecommended version: 1.4.21
Description: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a ...
Attack Vector: NETWORK
Attack Complexity: LOW
Exploitable Path: ignoreUnknownElements@...sLessonTest.java - ... - ignoreUnknownElements@...eam/XStream.java

ID: 9Ll1ML84jQrxSyG2Yf4DU52kSH7n5VwvfaSovSZvKiQ%3D
Vulnerable Package
CRITICAL CVE-2021-21347 Maven-com.thoughtworks.xstream:xstream-1.4.5
detailsRecommended version: 1.4.21
Description: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a ...
Attack Vector: NETWORK
Attack Complexity: LOW
Exploitable Path: alias@...nerableComponentsLessonTest.java - ... - alias@...houghtworks/xstream/XStream.java

ID: ZsgTzzHqhtQrI8MAkpcgsYaUncJLo5Em%2BMbjZ7xpn%2Fs%3D
Vulnerable Package
CRITICAL CVE-2021-21350 Maven-com.thoughtworks.xstream:xstream-1.4.5
detailsRecommended version: 1.4.21
Description: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a ...
Attack Vector: NETWORK
Attack Complexity: LOW
Exploitable Path: alias@...nerableComponentsLessonTest.java - ... - alias@...houghtworks/xstream/XStream.java

ID: oj3YOdeYi6oQ6eN2OollKtIm8H8L4Bt7gfPfHXZdIOc%3D
Vulnerable Package
CRITICAL CVE-2021-21351 Maven-com.thoughtworks.xstream:xstream-1.4.5
detailsRecommended version: 1.4.21
Description: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote...
Attack Vector: NETWORK
Attack Complexity: LOW
Exploitable Path: ignoreUnknownElements@...sLessonTest.java - ... - ignoreUnknownElements@...eam/XStream.java

ID: 8Z%2BLW3C3vDd7wuDL7yF8oqMkRSaZAF8Nu7AsTqmmcGg%3D
Vulnerable Package
CRITICAL CVE-2021-43466 Maven-org.thymeleaf:thymeleaf-spring5-3.0.12.RELEASE
detailsRecommended version: 3.0.13.RELEASE
Description: In the thymeleaf-spring3:3.0.12, thymeleaf-spring4:3.0.12, thymeleaf-spring5:3.0.12 components, thymeleaf combined with specific scenarios in templ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Ey6W0VlXNPJU1lWbh5yDDFAKbyFwirQ%2FB7YrFDPxH9w%3D
Vulnerable Package
CRITICAL CVE-2022-1471 Maven-org.yaml:snakeyaml-1.28
detailsRecommended version: 2.0
Description: SnakeYaml's "Constructor()" class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: QvKaEDq0Ul4XMxguE5I6%2Bes7atT1osokvzPclxFtbMI%3D
Vulnerable Package
CRITICAL CVE-2022-21724 Maven-org.postgresql:postgresql-42.2.23
detailsRecommended version: 42.2.29
Description: pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. T...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: aEKi20Vvto9hkUxOyCADud7K4acmtc7DUWuBlX3EACQ%3D
Vulnerable Package
CRITICAL CVE-2022-22965 Maven-org.springframework:spring-beans-5.3.9
detailsRecommended version: 5.3.31-wso2v1
Description: spring or spring-beans running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the appli...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: hAouY8jWZnK8ts6UYRD3pR7pfY2jbQDzzUbcmZhnWGU%3D
Vulnerable Package
CRITICAL CVE-2022-22965 Maven-org.springframework:spring-webmvc-5.3.9
detailsRecommended version: 5.3.39-atlassian-3
Description: spring or spring-beans running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the appli...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: ito%2BvHjRABw%2FRVFTUSqAQFEbaJGdKkts%2BSlUwb%2F4w5k%3D
Vulnerable Package
CRITICAL CVE-2022-22978 Maven-org.springframework.security:spring-security-web-5.5.2
detailsRecommended version: 5.7.14
Description: In Spring Security, module "spring-security-web", versions before 5.5.7, and 5.6.x before 5.6.4, RegexRequestMatcher can easily be misconfigured to...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: R1i54LgtwJDUoZNVH9ysvbjOYhlbcdk8%2Ba12O9tAK%2B8%3D
Vulnerable Package
CRITICAL CVE-2022-26520 Maven-org.postgresql:postgresql-42.2.23
detailsRecommended version: 42.2.29
Description: In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files t...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: PLXGgqDvlNviG2Cza0MtY3JhHzw%2BRqROnYODr%2BKHWTU%3D
Vulnerable Package
CRITICAL CVE-2022-41853 Maven-org.hsqldb:hsqldb-2.5.2
detailsRecommended version: 2.7.1
Description: Those using "java.sql.Statement" or "java.sql.PreparedStatement" in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a Re...
Attack Vector: NETWORK
Attack Complexity: LOW
Exploitable Path: shutdownCatalogs@...DBDatabaseConfig.java - ... - executeCompiledStatement@.../Session.java

ID: mkWiTVgc5P2yqMdoHBGcXC5rSE9edoHIOUSmuIOkAnI%3D
Vulnerable Package
CRITICAL CVE-2023-20873 Maven-org.springframework.boot:spring-boot-actuator-autoconfigure-2.5.4
detailsRecommended version: 3.3.11
Description: In Spring Boot versions 2.5.x prior to 2.5.15, 2.6.x prior to 2.6.15, 2.7.x prior to 2.7.11, and 3.x prior to 3.0.6, an application that is deploye...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: f6FplyzWdstV1Qvx8FNFe2YaMZMjxTEh5M3INv10w8Q%3D
Vulnerable Package
CRITICAL CVE-2023-34034 Maven-org.springframework.security:spring-security-web-5.5.2
detailsRecommended version: 5.7.14
Description: In Spring Security configuration using "**" as a pattern for WebFlux, creates a mismatch in pattern matching between Spring Security and Spring Web...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: gOwV50UslEGv7FmWnE7bxQldTRz%2FgZQ16czTF5ObHGk%3D
Vulnerable Package
CRITICAL CVE-2023-34034 Maven-org.springframework.security:spring-security-config-5.5.2
detailsRecommended version: 5.7.14
Description: In Spring Security configuration using "**" as a pattern for WebFlux, creates a mismatch in pattern matching between Spring Security and Spring Web...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: jugmCmlI1ez7RuICLt3nzf9OFQr%2Bxy8m6YO8s6s%2BVsM%3D
Vulnerable Package
CRITICAL CVE-2024-1597 Maven-org.postgresql:postgresql-42.2.23
detailsRecommended version: 42.2.29
Description: The pgjdbc, the PostgreSQL JDBC Driver, allows an attacker to inject SQL if using "PreferQueryMode=SIMPLE". Note this is not the default. In the de...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: TeAvZvM1%2Fvu%2BptmdkTj0HfRQsLlk6xOYxDltLTd14lY%3D
Vulnerable Package
CRITICAL CVE-2024-31573 Maven-org.xmlunit:xmlunit-core-2.8.2
detailsRecommended version: 2.10.0
Description: XMLUnit for Java has Insecure Defaults when Processing XSLT Stylesheets. This issue affects the package org.xmlunit:xmlunit-core versions prior to ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: uwPEUJns0kI9hcfDDB1qLVv68iFXGAhmZha%2Bc7AHBU8%3D
Vulnerable Package
CRITICAL CVE-2024-38821 Maven-org.springframework.security:spring-security-web-5.5.2
detailsRecommended version: 5.7.14
Description: Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: InIhEjYsWsdu5AgN2FxkyqBeGJN9w0DvyMs8aWRjQlc%3D
Vulnerable Package
CRITICAL CVE-2025-4641 Maven-io.github.bonigarcia:webdrivermanager-4.3.1
detailsRecommended version: 6.1.0
Description: An Improper Restriction of XML External Entity Reference vulnerability in Bonigarcia's WebDriverManager on Windows, macOS, and Linux (affecting XML...
Attack Vector: NETWORK
Attack Complexity: LOW
Exploitable Path: setup@.../owasp/webgoat/SeleniumTest.java - ... - loadXML@...rcia/wdm/WebDriverManager.java

ID: RxtBhv6%2B81kyIprWDbMdAfEC1ha3GOxpz7GWkHzOgWY%3D
Vulnerable Package
CRITICAL Cx06bea32e-26f2 Maven-org.postgresql:postgresql-42.2.23
detailsRecommended version: 42.2.29
Description: An arbitrary file write vulnerability in postgresql from 42.1.0 through 42.3.2 can lead to remote code execution when specifying an arbitrary filen...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: sw42AYkiqe1aqnT6eGTG1Z2%2B6%2FV5PGPu%2FnseptBM5Hc%3D
Vulnerable Package
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/advanced/SqlInjectionChallengeLogin.java: 46
detailsThe application's login method executes an SQL query with executeQuery, at line 51 of /webgoat-lessons/sql-injection/src/main/java/org/owasp/webg...
ID: S6oPS4zb2ahGYFdYnxLfWCTSWV0%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/advanced/SqlInjectionChallengeLogin.java: 46
detailsThe application's login method executes an SQL query with executeQuery, at line 51 of /webgoat-lessons/sql-injection/src/main/java/org/owasp/webg...
ID: 9MuFIJ%2BKTENCyxM8sOe3YFbGeoA%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson3.java: 56
detailsThe application's injectableQuery method executes an SQL query with executeUpdate, at line 65 of /webgoat-lessons/sql-injection/src/main/java/org...
ID: TSvJIZ8W1yfMtPmv5jW92SiC2%2FA%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson4.java: 56
detailsThe application's injectableQuery method executes an SQL query with executeUpdate, at line 63 of /webgoat-lessons/sql-injection/src/main/java/org...
ID: 7Ho7HUBxKfFnLEZvGLLtL6ncR2w%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson2.java: 55
detailsThe application's injectableQuery method executes an SQL query with executeQuery, at line 62 of /webgoat-lessons/sql-injection/src/main/java/org/...
ID: J8MlnQnx8Zc8AzgqCoGq5k%2FOy8E%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/jwt/src/main/java/org/owasp/webgoat/jwt/JWTFinalEndpoint.java: 92
detailsThe application's resolveSigningKeyBytes method executes an SQL query with executeQuery, at line 94 of /webgoat-lessons/jwt/src/main/java/org/owas...
ID: 4aJSmlwDj6I9F1lP0MgcmEKadoU%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/advanced/SqlInjectionChallenge.java: 56
detailsThe application's registerNewUser method executes an SQL query with executeQuery, at line 65 of /webgoat-lessons/sql-injection/src/main/java/org/...
ID: QXzl9Q4wWng%2BhgsZq1NqZ16sHn4%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson5b.java: 51
detailsThe application's injectableQuery method executes an SQL query with executeQuery, at line 71 of /webgoat-lessons/sql-injection/src/main/java/org/...
ID: MBG4%2BtcTciae%2F6KAzVaVdDsbDLY%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/mitigation/SqlOnlyInputValidation.java: 48
detailsThe application's injectableQuery method executes an SQL query with executeQuery, at line 67 of /webgoat-lessons/sql-injection/src/main/java/org/...
ID: JfdDbQaTiUOwNUIjGvic%2FYpam8w%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson9.java: 55
detailsThe application's log method executes an SQL query with executeUpdate, at line 138 of /webgoat-lessons/sql-injection/src/main/java/org/owasp/webg...
ID: Wem%2FVhHnYp0BM6l4eKzLOTxHioo%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson9.java: 55
detailsThe application's injectableQueryIntegrity method executes an SQL query with executeQuery, at line 66 of /webgoat-lessons/sql-injection/src/main/...
ID: 3MNoaMjLKwxePBZ%2FwEawGvW2w%2Bg%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson9.java: 55
detailsThe application's log method executes an SQL query with executeUpdate, at line 138 of /webgoat-lessons/sql-injection/src/main/java/org/owasp/webg...
ID: 05RW01nM4gxI4R8GWaZay%2FzizKw%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson9.java: 55
detailsThe application's injectableQueryIntegrity method executes an SQL query with executeQuery, at line 66 of /webgoat-lessons/sql-injection/src/main/...
ID: mmZ8LDdqnQdJqg21dgGo4xPP3yg%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson8.java: 54
detailsThe application's log method executes an SQL query with executeUpdate, at line 138 of /webgoat-lessons/sql-injection/src/main/java/org/owasp/webg...
ID: VydfScg5vlX4qnsk%2F5Ie865voR4%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson8.java: 54
detailsThe application's injectableQueryConfidentiality method executes an SQL query with executeQuery, at line 66 of /webgoat-lessons/sql-injection/src...
ID: qP%2F234MEtyPKLJGeTkWT2iTDyQM%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson8.java: 54
detailsThe application's log method executes an SQL query with executeUpdate, at line 138 of /webgoat-lessons/sql-injection/src/main/java/org/owasp/webg...
ID: l%2FljugTp4LagkV%2FrVfnTG%2FpHGqI%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson8.java: 54
detailsThe application's injectableQueryConfidentiality method executes an SQL query with executeQuery, at line 66 of /webgoat-lessons/sql-injection/src...
ID: BWJXnfrMlndCc0uV4mzVW13JzGU%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson5a.java: 53
detailsThe application's injectableQuery method executes an SQL query with executeQuery, at line 62 of /webgoat-lessons/sql-injection/src/main/java/org/...
ID: PgMXjc7lQnb8zWKG7TsF%2B9fzpPc%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson5a.java: 53
detailsThe application's injectableQuery method executes an SQL query with executeQuery, at line 62 of /webgoat-lessons/sql-injection/src/main/java/org/...
ID: E4ccb0gBIknOnadXf3HKFmpfQtA%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson5a.java: 53
detailsThe application's injectableQuery method executes an SQL query with executeQuery, at line 62 of /webgoat-lessons/sql-injection/src/main/java/org/...
ID: Xu8bVwS5%2BCouejc37AZMClEGI60%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson10.java: 52
detailsThe application's injectableQueryAvailability method executes an SQL query with executeQuery, at line 63 of /webgoat-lessons/sql-injection/src/ma...
ID: 3YX8I65Gj%2Fi0RLD9ufxnK1%2FcM8Y%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/advanced/SqlInjectionLesson6a.java: 51
detailsThe application's injectableQuery method executes an SQL query with executeQuery, at line 67 of /webgoat-lessons/sql-injection/src/main/java/org/...
ID: 04eHKpHzq4QjzcaX33wQhBeM8SA%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/mitigation/Servers.java: 67
detailsThe application's sort method executes an SQL query with executeQuery, at line 72 of /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgo...
ID: yjaPlJLWgoXDy4Pu%2Bu2eX8ZRzPA%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/challenge/src/main/java/org/owasp/webgoat/challenges/challenge5/Assignment5.java: 52
detailsThe application's login method executes an SQL query with executeQuery, at line 61 of /webgoat-lessons/challenge/src/main/java/org/owasp/webgoat/c...
ID: 29Fs9RZe5FlZapyxgELwTycayps%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/challenge/src/main/java/org/owasp/webgoat/challenges/challenge5/Assignment5.java: 52
detailsThe application's login method executes an SQL query with executeQuery, at line 61 of /webgoat-lessons/challenge/src/main/java/org/owasp/webgoat/c...
ID: 4bXENPgtbcCTz8Q41O0vUpzAvOE%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/introduction/SqlInjectionLesson5.java: 65
detailsThe application's injectableQuery method executes an SQL query with executeQuery, at line 72 of /webgoat-lessons/sql-injection/src/main/java/org/...
ID: T1gLzSDalRTgYVuIutcqG%2BsAX1w%3D
Attack Vector
CRITICAL SQL_Injection /webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/sql_injection/mitigation/SqlOnlyInputValidationOnKeywords.java: 48
detailsThe application's injectableQuery method executes an SQL query with executeQuery, at line 67 of /webgoat-lessons/sql-injection/src/main/java/org/...
ID: x97yk1yi4DSTes2n%2BGtcHzOzg4k%3D
Attack Vector
HIGH Absolute_Path_Traversal /webwolf/src/main/java/org/owasp/webwolf/FileServer.java: 69
detailsMethod importFile at line 69 of /webwolf/src/main/java/org/owasp/webwolf/FileServer.java gets dynamic data from the myFile element. This element’...
ID: qS5ZYdazs71Pu3VV%2BEjYOVWS%2FrM%3D
Attack Vector
HIGH Absolute_Path_Traversal /webgoat-lessons/path-traversal/src/main/java/org/owasp/webgoat/path_traversal/ProfileZipSlip.java: 36
detailsMethod uploadFileHandler at line 36 of /webgoat-lessons/path-traversal/src/main/java/org/owasp/webgoat/path_traversal/ProfileZipSlip.java gets ...
ID: gjEpLAtutTj98cFrH3KJ76FwMgU%3D
Attack Vector
HIGH Absolute_Path_Traversal /webgoat-lessons/path-traversal/src/main/java/org/owasp/webgoat/path_traversal/ProfileZipSlip.java: 36
detailsMethod uploadFileHandler at line 36 of /webgoat-lessons/path-traversal/src/main/java/org/owasp/webgoat/path_traversal/ProfileZipSlip.java gets ...
ID: WHy96c4vwS6VsW2zoAbjjy%2FdDOE%3D
Attack Vector
HIGH Absolute_Path_Traversal /webgoat-lessons/path-traversal/src/main/java/org/owasp/webgoat/path_traversal/ProfileUploadRemoveUserInput.java: 26
detailsMethod uploadFileHandler at line 26 of /webgoat-lessons/path-traversal/src/main/java/org/owasp/webgoat/path_traversal/ProfileUploadRemoveUserInp...
ID: ggj%2FmkQIinaxXwoy2pUmhdGoFH4%3D
Attack Vector
HIGH Absolute_Path_Traversal /webgoat-lessons/path-traversal/src/main/java/org/owasp/webgoat/path_traversal/ProfileUploadFix.java: 29
detailsMethod uploadFileHandler at line 29 of /webgoat-lessons/path-traversal/src/main/java/org/owasp/webgoat/path_traversal/ProfileUploadFix.java get...
ID: hDARed1hDXuX%2BLXhsstJ1GiOmiE%3D
Attack Vector
HIGH Absolute_Path_Traversal /webgoat-lessons/path-traversal/src/main/java/org/owasp/webgoat/path_traversal/ProfileUpload.java: 28
detailsMethod uploadFileHandler at line 28 of /webgoat-lessons/path-traversal/src/main/java/org/owasp/webgoat/path_traversal/ProfileUpload.java gets d...
ID: %2FQUnguucUpfShC4uQnKUms%2B2ff8%3D
Attack Vector
HIGH CVE-2016-3674 Maven-com.thoughtworks.xstream:xstream-1.4.5
detailsRecommended version: 1.4.21
Description: Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) Sta...
Attack Vector: NETWORK
Attack Complexity: LOW
Exploitable Path: fromXML@...rableComponentsLessonTest.java - ... - createInputFactory@...dardStaxDriver.java

ID: ne4NtUS0uf8%2FLQfsi9IQ2Y9T6ZXEqyQ6ZNP01SBkog0%3D
Vulnerable Package
HIGH CVE-2017-7957 Maven-com.thoughtworks.xstream:xstream-1.4.5
detailsRecommended version: 1.4.21
Description: XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' duri...
Attack Vector: NETWORK
Attack Complexity: LOW
Exploitable Path: fromXML@...rableComponentsLessonTest.java - ... - fromXML@...ughtworks/xstream/XStream.java

ID: 6oeiiapu1V2Gb5GjtzIHhxOmVrVY38YJ62l7SntCIiA%3D
Vulnerable Package
HIGH CVE-2020-26217 Maven-com.thoughtworks.xstream:xstream-1.4.5
detailsRecommended version: 1.4.21
Description: XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands ...
Attack Vector: NETWORK
Attack Complexity: LOW
Exploitable Path: fromXML@...rableComponentsLessonTest.java - ... - fromXML@...ughtworks/xstream/XStream.java

ID: bJMsCou%2BVeKMXTqgjQQjJgIYRzlq1yKZiL1XNTj6%2Bl8%3D
Vulnerable Package
HIGH CVE-2020-26258 Maven-com.thoughtworks.xstream:xstream-1.4.5
detailsRecommended version: 1.4.21
Description: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability...
Attack Vector: NETWORK
Attack Complexity: LOW
Exploitable Path: fromXML@...rableComponentsLessonTest.java - ... - fromXML@...ughtworks/xstream/XStream.java

ID: 53X6bFuHkGs%2BrLHHzss8RxKtDwZPX5MOzzoWrMP7mno%3D
Vulnerable Package

More results are available on the CxOne platform

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants