io.dropwizard:dropwizard-validation@1.3.8 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the io.dropwizard:dropwizard-validation package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Remote Code Execution (RCE)

io.dropwizard:dropwizard-validation is a simple library for building production-ready RESTful web services.

Affected versions of this package are vulnerable to Remote Code Execution (RCE). A server-side template injection was identified in the self-validating feature enabling attackers to inject arbitrary Java EL expressions, leading to Remote Code Execution (RCE) vulnerability.

How to fix Remote Code Execution (RCE)?

Upgrade io.dropwizard:dropwizard-validation to version 1.3.21, 2.0.3 or higher.

[1.3.0,1.3.21) [2.0.0,2.0.3)
  • H
Remote Code Execution (RCE)

io.dropwizard:dropwizard-validation is a simple library for building production-ready RESTful web services.

Affected versions of this package are vulnerable to Remote Code Execution (RCE). An attacker is able to inject arbitrary Java Expression Language expressions when using the self-validating feature.

How to fix Remote Code Execution (RCE)?

Upgrade io.dropwizard:dropwizard-validation to version 1.3.19, 2.0.2 or higher.

[1.3.0-rc1,1.3.19) [2.0.0,2.0.2)