com.exadel.flamingo.flex:amf-serializer@1.0.0 vulnerabilities
-
latest version
1.5.0
-
first published
16 years ago
-
latest version published
16 years ago
-
licenses detected
- [1.0.0,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the com.exadel.flamingo.flex:amf-serializer package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
|
[1.0.0,1.5.0]
|
|
[1.0.0,1.5.0]
|
com.exadel.flamingo.flex:amf-serializer is a library for AMF0/AMF3 messages serialization/deserialization. Affected versions of this package are vulnerable to XML External Entity (XXE) Injection. The AMF3 deserializers in this library allow external entity (XXE) referenced from XML documents embedded in AMF3 messages. How to fix XML External Entity (XXE) Injection? There is no fixed version for |
[1.0.0,)
|