io.dropwizard:dropwizard-validation@1.3.15 vulnerabilities

  • latest version

    4.0.13

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    14 days ago

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the io.dropwizard:dropwizard-validation package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Remote Code Execution (RCE)

    io.dropwizard:dropwizard-validation is a simple library for building production-ready RESTful web services.

    Affected versions of this package are vulnerable to Remote Code Execution (RCE). A server-side template injection was identified in the self-validating feature enabling attackers to inject arbitrary Java EL expressions, leading to Remote Code Execution (RCE) vulnerability.

    How to fix Remote Code Execution (RCE)?

    Upgrade io.dropwizard:dropwizard-validation to version 1.3.21, 2.0.3 or higher.

    [1.3.0,1.3.21)[2.0.0,2.0.3)
    • H
    Remote Code Execution (RCE)

    io.dropwizard:dropwizard-validation is a simple library for building production-ready RESTful web services.

    Affected versions of this package are vulnerable to Remote Code Execution (RCE). An attacker is able to inject arbitrary Java Expression Language expressions when using the self-validating feature.

    How to fix Remote Code Execution (RCE)?

    Upgrade io.dropwizard:dropwizard-validation to version 1.3.19, 2.0.2 or higher.

    [1.3.0-rc1,1.3.19)[2.0.0,2.0.2)