Provides transitive vulnerable dependency maven:com.fasterxml.jackson.core:jackson-databind:2.10.2 CVE-2020-25649 7.5 Improper Restriction of XML External Entity Reference vulnerability pending CVSS allocation CVE-2021-20190 8.1 Deserialization of Untrusted Data vulnerability pending CVSS allocation CVE-2020-10650 8.1 Deserialization of Untrusted Data vulnerability with high severity found Cxced0c06c-935c 5.9 Uncontrolled Resource Consumption vulnerability pending CVSS allocation CVE-2020-36518 7.5 Out-of-bounds Write vulnerability pending CVSS allocation CVE-2022-42003 7.5 Deserialization of Untrusted Data vulnerability pending CVSS allocation CVE-2022-42004 7.5 Deserialization of Untrusted Data vulnerability pending CVSS allocation Results powered by Checkmarx(c)
时间: 2023-04-03 14:03:03 浏览: 404
这是一个关于漏洞的问题,我可以回答。这个问题提供了一些 Maven 依赖的漏洞信息,包括 CVE 编号、漏洞类型和 CVSS 分数等。这些漏洞可能会导致 XML 外部实体引用、反序列化不受信任的数据、资源消耗不受控制、越界写等问题。这些漏洞需要及时修复,以确保系统的安全性。
相关问题
Provides transitive vulnerable dependency maven:org.apache.tomcat.embed:tomcat-embed-core:9.0.69 CVE-2023-28708 7.5 Unprotected Transport of Credentials vulnerability pending CVSS allocation Results powered by Checkmarx(c)
这似乎不是一个问题,而是一个关于 Maven 依赖漏洞的报告。这个报告指出了 Maven 项目中使用的 org.apache.tomcat.embed:tomcat-embed-core:9.0.69 存在一个未受保护的凭据传输漏洞(Unprotected Transport of Credentials vulnerability),CVE 编号为 2023-28708,CVSS 暂未分配。建议你查看 Maven 项目中使用的依赖项,并考虑更新到修复漏洞的版本。
Provides transitive vulnerable dependency maven:org.codehaus.jettison:jettison:1.1
This Maven dependency has a transitive vulnerable dependency on jettison version 1.1, which may have security vulnerabilities that could be exploited by attackers. It is recommended to update the dependency to a newer version that does not have these vulnerabilities.
阅读全文
相关推荐

















