0.73.0
7 years ago
15 days ago
Known vulnerabilities in the com.linecorp.centraldogma:centraldogma-server package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
com.linecorp.centraldogma:centraldogma-server is a service configuration repository based on Git, ZooKeeper and HTTP/2 (centraldogma-server). Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to insufficient input validation and output encoding. An attacker can inject malicious scripts into web pages viewed by other users by submitting crafted input. How to fix Cross-site Scripting (XSS)? Upgrade | [,0.64.0) |
com.linecorp.centraldogma:centraldogma-server is a service configuration repository based on Git, ZooKeeper and HTTP/2 (centraldogma-server). Affected versions of this package are vulnerable to Privilege Escalation. This can happen by mirroring to the internal dogma repository that has a file managing the authorization of the project. How to fix Privilege Escalation? Upgrade | [,0.52.0) |