Skip to main content

Vendor/product archive

apache / olingo CVEs

Beta · best-effort

4 CVEs tagged to apache / olingo1 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2020-1925

Published Jan 9, 2020

Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or DELETE request to this URL. It…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17555

Published Dec 4, 2019

The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method without any check. If a malicio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17556

Published Dec 4, 2019

Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-17554

Published Dec 4, 2019

The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "applica…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1