github.com/xkcoding/spring-boot-demo
Submitted 8/4/2026, 10:28:00 AM · Status: ok
Risk grade
F
100 / 100
Findings
523
100 critical41 high346 medium36 low0 info0 on CISA KEV0ATT&CK
Showing 523 of 523 findings
Findings
- Arbitrary code execution in Apache Commons TextgrypeCVE-2022-42889EPSS 99.9%
- Authentication bypass in Apache ShirogrypeCVE-2020-17523EPSS 85.9%
- Cross-site scripting in Swagger-UIgrypeCVE-2019-17495EPSS 5.6%
- Dromara Hutool Deserialization of Untrusted Data vulnerabilitygrypeCVE-2023-24162EPSS 1.3%
- Dromara hutool vulnerable to SQL InjectiongrypeCVE-2023-24163EPSS 1.4%
- XXL-JOB contains a Command execution vulnerability in background tasksgrypeCVE-2022-40929EPSS 1.3%
- apache-commons-text: variable interpolation RCEApache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs …trivyCVE-2022-42889
- apache-commons-text: variable interpolation RCEApache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs …trivyCVE-2022-42889
- Cross-site scripting in Swagger-UIA Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product in…trivyCVE-2019-17495
- Cross-site scripting in Swagger-UIA Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product in…trivyCVE-2019-17495
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara Hutool Deserialization of Untrusted Data vulnerabilityDeserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.trivyCVE-2023-24162
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- Dromara hutool vulnerable to SQL InjectionSQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.trivyCVE-2023-24163
- shiro: Authentication bypass through specially crafted HTTP requestApache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.trivyCVE-2020-17523
- shiro: Authentication bypass through specially crafted HTTP requestApache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.trivyCVE-2020-17523
- XXL-JOB contains a Command execution vulnerability in background tasksXXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).trivyCVE-2022-40929
- XXL-JOB contains a Command execution vulnerability in background tasksXXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).trivyCVE-2022-40929
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Elasticsearch vulnerable to Uncontrolled Resource ConsumptiongrypeCVE-2023-31418EPSS 1.2%
- Improper Preservation of Permissions in xxl-jobgrypeCVE-2024-42681EPSS 0.9%
- Improper Privilege Management in ElasticsearchgrypeCVE-2020-7009EPSS 1.6%
- MySQL Connectors takeover vulnerabilitygrypeCVE-2023-22102EPSS 0.9%
- XXL-JOB vulnerable to Server-Side Request Forgery (SSRF)grypeCVE-2022-43183EPSS 1.6%
- Dynamic code execution via eval()/new Function() — arbitrary-code-execution risk if any operand is attacker-influenced. Avoid; parse explicitly. (Apache-2.0.)Dynamic code execution via eval()/new Function() — arbitrary-code-execution risk if any operand is attacker-influenced. Avoid; parse explicitly. (Apache-2.0.)semgrepdemo-websocket-socketio/src/main/resources/static/js/socket.io/socket.io.js:3
- Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, aHardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)semgrepdemo-oauth/oauth-authorization-server/README.adoc:105
- Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, aHardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)semgrepdemo-oauth/oauth-authorization-server/README.adoc:141
- Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, aHardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)semgrepdemo-oauth/oauth-authorization-server/README.adoc:107
- Deprecated MAINTAINER usedMAINTAINER has been deprecated since Docker 1.13.0.trivydemo-docker/Dockerfile:5
- elasticsearch: Generating API keys with specific steps could result in generating API key with elevated privilegesElasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevate…trivyCVE-2020-7009
- elasticsearch: Generating API keys with specific steps could result in generating API key with elevated privilegesElasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevate…trivyCVE-2020-7009
- elasticsearch: uncontrolled resource consumptionAn issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elasti…trivyCVE-2023-31418
- elasticsearch: uncontrolled resource consumptionAn issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elasti…trivyCVE-2023-31418
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivydemo-docker/Dockerfile:0
- Improper Preservation of Permissions in xxl-jobInsecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.trivyCVE-2024-42681
- Improper Preservation of Permissions in xxl-jobInsecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.trivyCVE-2024-42681
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2023)Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Con…trivyCVE-2023-22102
- XXL-JOB vulnerable to Server-Side Request Forgery (SSRF)XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.trivyCVE-2022-43183
- XXL-JOB vulnerable to Server-Side Request Forgery (SSRF)XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.trivyCVE-2022-43183
This report is public.