VulnSea

api_gateway vulnerabilities

CVEs whose affected-version data names the api_gateway package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2020-11979High· 7.5
6y ago

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new…

▾ Twilightapache · antEPSS 8.0%via NVD
CVE-2018-5407Medium· 4.7PoC
7y ago

Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.

Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.

▾ Twilightnodejs · node.jsEPSS 3.4%via NVD
CVE-2018-0734Medium· 5.9
7y ago

The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack

The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in…

▾ Sunlitopenssl · opensslEPSS 12%via NVD
CVE-2018-0735Medium· 5.9
7y ago

The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack

The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i).…

▾ Sunlitopenssl · opensslEPSS 4.7%via NVD
CVE-2017-5645Critical· 9.8PoC
9y ago

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitr…

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitr…

▾ Abyssalapache · log4jEPSS 90%via NVD
api_gateway vulnerabilities (CVEs) · VulnSea