org.apache.cayenne:cayenne-server@4.0.M3 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.apache.cayenne:cayenne-server package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • C
Deserialization of Untrusted Data

org.apache.cayenne:cayenne-server is a library of all Cayenne "server" modules.

Affected versions of this package are vulnerable to Deserialization of Untrusted Data an attacker with client access to Cayenne ROP can transmit a malicious payload to any vulnerable third-party dependency on the server.

How to fix Deserialization of Untrusted Data?

Upgrade org.apache.cayenne:cayenne-server to version 4.2.B1 or higher.

[,4.2.B1)
  • H
XML External Entity (XXE) Injection

org.apache.cayenne:cayenne-server is an open source persistence framework licensed under the Apache License, providing object-relational mapping (ORM) and remoting services.

Affected versions of this package are vulnerable to XML External Entity (XXE) Injection. If an attacker tricks a user into opening a malicious XML file, they were able to instruct the XML parser to transfer files from a local machine to a remote machine controlled by the attacker.

How to fix XML External Entity (XXE) Injection?

Upgrade org.apache.cayenne:cayenne-server to versions 3.1.3, 4.0, 4.1.M2 or higher.

[3.1.0,3.1.3) [4.0.B1,4.0) [4.1.M1,4.1.M2)