← Scan another repo

github.com/xkcoding/spring-boot-demo

@ 87a142f9604c

Submitted 8/4/2026, 10:28:00 AM · Status: ok

Risk grade
F
100 / 100
Findings
523
100 critical41 high346 medium36 low0 info0 on CISA KEV0ATT&CK
Showing 523 of 523 findings

Findings

  • Arbitrary code execution in Apache Commons Text
    grypeCVE-2022-42889EPSS 99.9%
  • Authentication bypass in Apache Shiro
    grypeCVE-2020-17523EPSS 85.9%
  • Cross-site scripting in Swagger-UI
    grypeCVE-2019-17495EPSS 5.6%
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    grypeCVE-2023-24162EPSS 1.3%
  • Dromara hutool vulnerable to SQL Injection
    grypeCVE-2023-24163EPSS 1.4%
  • XXL-JOB contains a Command execution vulnerability in background tasks
    grypeCVE-2022-40929EPSS 1.3%
  • apache-commons-text: variable interpolation RCE
    Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs …
    trivyCVE-2022-42889
  • apache-commons-text: variable interpolation RCE
    Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs …
    trivyCVE-2022-42889
  • Cross-site scripting in Swagger-UI
    A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product in…
    trivyCVE-2019-17495
  • Cross-site scripting in Swagger-UI
    A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product in…
    trivyCVE-2019-17495
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara Hutool Deserialization of Untrusted Data vulnerability
    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
    trivyCVE-2023-24162
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • Dromara hutool vulnerable to SQL Injection
    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
    trivyCVE-2023-24163
  • shiro: Authentication bypass through specially crafted HTTP request
    Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
    trivyCVE-2020-17523
  • shiro: Authentication bypass through specially crafted HTTP request
    Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
    trivyCVE-2020-17523
  • XXL-JOB contains a Command execution vulnerability in background tasks
    XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).
    trivyCVE-2022-40929
  • XXL-JOB contains a Command execution vulnerability in background tasks
    XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).
    trivyCVE-2022-40929
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Elasticsearch vulnerable to Uncontrolled Resource Consumption
    grypeCVE-2023-31418EPSS 1.2%
  • Improper Preservation of Permissions in xxl-job
    grypeCVE-2024-42681EPSS 0.9%
  • Improper Privilege Management in Elasticsearch
    grypeCVE-2020-7009EPSS 1.6%
  • MySQL Connectors takeover vulnerability
    grypeCVE-2023-22102EPSS 0.9%
  • XXL-JOB vulnerable to Server-Side Request Forgery (SSRF)
    grypeCVE-2022-43183EPSS 1.6%
  • Dynamic code execution via eval()/new Function() — arbitrary-code-execution risk if any operand is attacker-influenced. Avoid; parse explicitly. (Apache-2.0.)
    Dynamic code execution via eval()/new Function() — arbitrary-code-execution risk if any operand is attacker-influenced. Avoid; parse explicitly. (Apache-2.0.)
    semgrepdemo-websocket-socketio/src/main/resources/static/js/socket.io/socket.io.js:3
  • Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, a
    Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)
    semgrepdemo-oauth/oauth-authorization-server/README.adoc:105
  • Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, a
    Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)
    semgrepdemo-oauth/oauth-authorization-server/README.adoc:141
  • Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, a
    Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)
    semgrepdemo-oauth/oauth-authorization-server/README.adoc:107
  • Deprecated MAINTAINER used
    MAINTAINER has been deprecated since Docker 1.13.0.
    trivydemo-docker/Dockerfile:5
  • elasticsearch: Generating API keys with specific steps could result in generating API key with elevated privileges
    Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevate…
    trivyCVE-2020-7009
  • elasticsearch: Generating API keys with specific steps could result in generating API key with elevated privileges
    Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevate…
    trivyCVE-2020-7009
  • elasticsearch: uncontrolled resource consumption
    An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elasti…
    trivyCVE-2023-31418
  • elasticsearch: uncontrolled resource consumption
    An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elasti…
    trivyCVE-2023-31418
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivydemo-docker/Dockerfile:0
  • Improper Preservation of Permissions in xxl-job
    Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.
    trivyCVE-2024-42681
  • Improper Preservation of Permissions in xxl-job
    Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.
    trivyCVE-2024-42681
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)
    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…
    trivyCVE-2023-22102
  • XXL-JOB vulnerable to Server-Side Request Forgery (SSRF)
    XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
    trivyCVE-2022-43183
  • XXL-JOB vulnerable to Server-Side Request Forgery (SSRF)
    XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
    trivyCVE-2022-43183

This report is public.