Skip to main content

Vendor/product archive

redhat / jboss_fuse CVEs

Beta · best-effort

41 CVEs tagged to redhat / jboss_fuse5 Critical, 17 High, 15 Medium, 4 Low, 0 Unrated.

CVE-2024-7885

Published Aug 21, 2024

A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyPro…

CVSS 7.5 · High

CVE-2022-4492

Published Feb 23, 2023

The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by def…

CVSS 7.5 · High

CVE-2021-20218

Published Mar 16, 2021

A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client…

CVSS 7.4 · High

CVE-2020-25689

Published Nov 2, 2020

A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly c…

CVSS 5.3 · Medium

CVE-2020-25644

Published Oct 6, 2020

A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of s…

CVSS 7.5 · High

CVE-2020-10718

Published Sep 16, 2020

A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed process API has an exposed setting of the Thread Context Classloader (TCCL). This sett…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14892

Published Mar 2, 2020

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-co…

CVSS 9.8 · Critical
Showing 1-25 of 41 CVEsPage 1 of 2