0.23.37
9 years ago
14 days ago
Known vulnerabilities in the org.http4s:http4s-server_2.12 package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.http4s:http4s-server_2.12 is a base library for building http4s servers. Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | [,0.23.35) |
org.http4s:http4s-server_2.12 is a base library for building http4s servers. Affected versions of this package are vulnerable to Replay Attack through improper handling of the How to fix Replay Attack? Upgrade | [,0.23.35) |
org.http4s:http4s-server_2.12 is a base library for building http4s servers. Affected versions of this package are vulnerable to Missing Release of Memory after Effective Lifetime via the How to fix Missing Release of Memory after Effective Lifetime? Upgrade | [,0.23.35) |
org.http4s:http4s-server_2.12 is a base library for building http4s servers. Affected versions of this package are vulnerable to Origin Validation Error. In http4s, the default CORS configuration is vulnerable to an origin reflection attack. The middleware is also susceptible to a Null Origin Attack. The original How to fix Origin Validation Error? Upgrade | [,0.21.27)[0.22.0,0.22.3)[0.23.0,0.23.2)[1.0.0-M2,1.0.0-M25) |
org.http4s:http4s-server_2.12 is a base library for building http4s servers. Affected versions of this package are vulnerable to Local File Inclusion. This vulnerability applies to all users of How to fix Local File Inclusion? Upgrade | [0.21.0,0.21.2)[0.19.0,0.20.20)[,0.18.26) |