CVE Security Report - SICS Naming Service
The report contains data retrieved from the National Vulnerability Database: https://nvd.nist.gov, NPM Public Advisories: https://www.npmjs.com/advisories, and the RetireJS community.
| Name | Description | CWE | CVSS v2.0 Severity | CVSS v3.0 Severity | Dependency |
|---|---|---|---|---|---|
| CVE-2021-28170 | In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid. | CWE-20 | MEDIUM | MEDIUM | jakarta.el-api-3.0.2.jar |
| CVE-2020-29242 | dhowden tag before 2020-11-19 allows 'panic: runtime error: index out of range' via readPICFrame. | CWE-129 | MEDIUM | MEDIUM | jakarta.servlet.jsp.jstl-1.2.6.jar |
| CVE-2020-29243 | dhowden tag before 2020-11-19 allows 'panic: runtime error: index out of range' via readAPICFrame. | CWE-129 | MEDIUM | MEDIUM | jakarta.servlet.jsp.jstl-1.2.6.jar |
| CVE-2020-29244 | dhowden tag before 2020-11-19 allows 'panic: runtime error: slice bounds out of range' via readTextWithDescrFrame. | CWE-129 | MEDIUM | MEDIUM | jakarta.servlet.jsp.jstl-1.2.6.jar |
| CVE-2020-29245 | dhowden tag before 2020-11-19 allows 'panic: runtime error: slice bounds out of range' via readAtomData. | CWE-129 | MEDIUM | MEDIUM | jakarta.servlet.jsp.jstl-1.2.6.jar |
| CVE-2020-29242 | dhowden tag before 2020-11-19 allows 'panic: runtime error: index out of range' via readPICFrame. | CWE-129 | MEDIUM | MEDIUM | jakarta.servlet.jsp.jstl-api-1.2.4.jar |
| CVE-2020-29243 | dhowden tag before 2020-11-19 allows 'panic: runtime error: index out of range' via readAPICFrame. | CWE-129 | MEDIUM | MEDIUM | jakarta.servlet.jsp.jstl-api-1.2.4.jar |
| CVE-2020-29244 | dhowden tag before 2020-11-19 allows 'panic: runtime error: slice bounds out of range' via readTextWithDescrFrame. | CWE-129 | MEDIUM | MEDIUM | jakarta.servlet.jsp.jstl-api-1.2.4.jar |
| CVE-2020-29245 | dhowden tag before 2020-11-19 allows 'panic: runtime error: slice bounds out of range' via readAtomData. | CWE-129 | MEDIUM | MEDIUM | jakarta.servlet.jsp.jstl-api-1.2.4.jar |
This report was generated 22.09.2021, 06:11:27 UTC, using dependency-check version: 6.0.3.