Vulnerabilities > Dropwizard

DATE CVE VULNERABILITY TITLE RISK
2020-04-10 CVE-2020-11002 Injection vulnerability in Dropwizard Validation
dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability.
network
low complexity
dropwizard CWE-74
8.8
2020-02-24 CVE-2020-5245 Injection vulnerability in multiple products
Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature. The issue has been fixed in dropwizard-validation 1.3.19 and 2.0.2.
network
low complexity
dropwizard oracle CWE-74
8.8