tech.powerjob:powerjob@4.3.2 vulnerabilities

  • latest version

    5.1.1

  • first published

    3 years ago

  • latest version published

    1 months ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the tech.powerjob:powerjob package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Information Exposure

    Affected versions of this package are vulnerable to Information Exposure via the interface for querying appId parameter to /container/list.

    How to fix Information Exposure?

    There is no fixed version for tech.powerjob:powerjob.

    [0,)
    • H
    Remote Code Execution (RCE)

    Affected versions of this package are vulnerable to Remote Code Execution (RCE) via the instanceId parameter, accessed at the /instance/detail endpoint.

    How to fix Remote Code Execution (RCE)?

    There is no fixed version for tech.powerjob:powerjob.

    [0,)
    • M
    Improper Access Control

    Affected versions of this package are vulnerable to Improper Access Control due to allowing an attacker to upload a maliciously crafter .jar file.

    How to fix Improper Access Control?

    There is no fixed version for tech.powerjob:powerjob.

    [0,)
    • H
    Insecure Permissions

    Affected versions of this package are vulnerable to Insecure Permissions via the job/list interface by allowing an attacker to send a maliciously crafted request.

    How to fix Insecure Permissions?

    There is no fixed version for tech.powerjob:powerjob.

    [0,)
    • M
    Access Control Bypass

    Affected versions of this package are vulnerable to Access Control Bypass via the user/save interface by allowing an attacker to send a maliciously crafted request.

    How to fix Access Control Bypass?

    There is no fixed version for tech.powerjob:powerjob.

    [0,)
    • C
    Remote Code Execution (RCE)

    Affected versions of this package are vulnerable to Remote Code Execution (RCE) due to unauthorized interfaces by allowing an attacker to send a maliciously crafted request.

    How to fix Remote Code Execution (RCE)?

    There is no fixed version for tech.powerjob:powerjob.

    [0,)