Vulnerabilities > Quarkus > Quarkus > 2.0.1

DATE CVE VULNERABILITY TITLE RISK
2021-05-26 CVE-2021-28170 Expression Language Injection vulnerability in multiple products
In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.
network
low complexity
eclipse quarkus oracle CWE-917
5.0
2021-04-13 CVE-2021-29428 Creation of Temporary File in Directory with Incorrect Permissions vulnerability in multiple products
In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it.
4.4
2021-04-13 CVE-2021-29427 Inclusion of Functionality from Untrusted Control Sphere vulnerability in multiple products
In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning.
6.0
2021-04-12 CVE-2021-29429 Insecure Temporary File vulnerability in multiple products
In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle.
1.9
2021-02-18 CVE-2020-28491 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1.
network
low complexity
fasterxml quarkus oracle CWE-770
7.5