VulnSea

cloud_secure_agent vulnerabilities

CVEs whose affected-version data names the cloud_secure_agent package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2022-22971Medium· 6.5PoC
4y ago

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

▾ Twilightvmware · spring_frameworkEPSS 3.2%via NVD
CVE-2022-22970Medium· 5.3PoC
4y ago

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field…

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field…

▾ Twilightvmware · spring_frameworkEPSS 2.0%via NVD
CVE-2022-22968Medium· 5.3PoC
4y ago

In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with b…

In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with b…

▾ Twilightvmware · spring_frameworkEPSS 5.7%via NVD
CVE-2021-21290Medium· 6.2
5y ago

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-lik…

▾ Sunlitnetty · nettyEPSS 1.8%via NVD
cloud_secure_agent vulnerabilities (CVEs) · VulnSea