io.vertx:vertx-web
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting io.vertx:vertx-webpage 1 of 1
- CVE-2018-12540HIGHCVSS 8.8EG 8.8✓ Fixed in 3.5.32018-07-12
vulnerable: 3.0.0 ... 3.5.3.CR1 (22 versions)
In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet.
- CVE-2018-12542CRITICALCVSS 9.8EG 9.8✓ Fixed in 3.5.42018-10-10
vulnerable: 3.0.0 ... 3.5.3.CR1 (23 versions)
In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\' (forward slashes) sequences that can reso…
- CVE-2019-17640CRITICALCVSS 9.8EG 9.8✓ Fixed in 3.9.42020-10-15
vulnerable: 3.0.0 ... 3.9.3 (43 versions)
In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Beta2, and 4.0.0.Beta3, StaticHandler doesn't correctly processes back slashes on Windows Ope…
- CVE-2020-35217HIGHCVSS 8.8EG 8.8✓ Fixed in 4.0.0-milestone52021-01-20
vulnerable: 4.0.0-milestone4
Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification. Instead of comparing the CSRF token in the request with the CSRF token in the cookie, it compares the CSRF token in the cookie against a CSRF token that …
- CVE-2023-24815MEDIUMCVSS 4.8EG 4.8✓ Fixed in 4.3.82023-02-09
vulnerable: 4.0.0 ... 4.3.7 (34 versions)
Vert.x-Web is a set of building blocks for building web applications in the java programming language. When running vertx web applications that serve files using `StaticHandler` on Windows Operating Systems and Windows File Systems, if the…
Check whether io.vertx:vertx-web is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for io.vertx:vertx-web CVEs against the assets you own.
Start Free Scan →