Vulnerabilities > Elide

DATE CVE VULNERABILITY TITLE RISK
2022-04-11 CVE-2022-24827 SQL Injection vulnerability in Elide 6.1.3
Elide is a Java library that lets you stand up a GraphQL/JSON-API web service with minimal effort.
network
high complexity
elide CWE-89
8.1
2020-03-30 CVE-2020-5289 Files or Directories Accessible to External Parties vulnerability in Elide
In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have access to assuming they can read at least one other field in the model.
network
low complexity
elide CWE-552
6.5