org.jboss:jboss-ejb-client@4.0.0.Beta14 vulnerabilities

  • latest version

    5.0.6.Final

  • latest non vulnerable version

  • first published

    13 years ago

  • latest version published

    3 months ago

  • licenses detected

    • [1.0.0.Beta10,1.0.0.Beta2); [1.0.0.Beta8,4.0.0.Beta25-jbossorg-1); [4.0.0.Beta3,4.0.0.Beta30); [4.0.0.Beta4,4.0.0.CR1)
  • package manager

Direct Vulnerabilities

Known vulnerabilities in the org.jboss:jboss-ejb-client package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Denial of Service (DoS)

org.jboss:jboss-ejb-client is a client library for EJB applications working against Wildfly.

Affected versions of this package are vulnerable to Denial of Service (DoS). A vulnerability was found in Wildfly's EJB Client, where accumulation of some specific EJB transaction objects in InvocationTracker may lead to DoS.

How to fix Denial of Service (DoS)?

Upgrade org.jboss:jboss-ejb-client to version 4.0.34.Final or higher.

[,4.0.34.Final)
  • M
Information Disclosure

org.jboss:jboss-ejb-client is a client library for EJB applications working against Wildfly.

Affected versions of this package are vulnerable to Information Disclosure. Publicly accessible privileged actions may lead to information disclosure on the server they are deployed on.

How to fix Information Disclosure?

Upgrade org.jboss:jboss-ejb-client to version 4.0.39.Final or higher.

[,4.0.39.Final)