6.7.2
6 years ago
15 days ago
Known vulnerabilities in the com.powsybl:powsybl-cgmes-conversion package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via the Note: This is only exploitable if an attacker can control both the regular expression input and the resource names being evaluated. How to fix Regular Expression Denial of Service (ReDoS)? Upgrade | [,6.7.2) |
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the Note: This is only exploitable if untrusted users are allowed to import untrusted CGMES or XIIDM network files. How to fix Server-side Request Forgery (SSRF)? Upgrade | [,6.7.2) |